CVE-2026-102675 Electron 自定义协议跨域脚本读取漏洞
影响攻击者可跨源读取自定义协议响应内容,导致敏感信息泄露
Electron 是使用 JavaScript、HTML 和 CSS 编写跨平台桌面应用的框架。在 41.10.6、42.9.2、43.4.1 和 44.0.0-beta.5 之前,通过 protocol.registerFileProtocol 或 protocol.registerHttpProtocol 为启用了 supportFetchAPI 但未启用 corsEnabled 的自定义 scheme 提供的响应,可能仍可被跨源脚本读取。该问题是对 CVE-2026-70604 修复的补充完善。
影响范围
Electron 41.10.6、42.9.2、43.4.1、44.0.0-beta.5 之前的版本;仅当应用暴露此类自定义 scheme 并在同一会话中加载不受信任内容时受影响。
漏洞详情
漏洞类型为跨源信息泄露。成因是自定义协议注册时启用了 supportFetchAPI 却未启用 corsEnabled,导致响应缺少正确的跨源隔离限制,脚本可跨源读取其内容。攻击者需诱导应用在同一会话中加载恶意内容,再通过脚本读取该协议响应。
利用条件与风险
利用前提是应用注册了此类自定义 scheme 且在同一会话中加载不受信任内容;实战中可能导致本地文件或敏感数据被恶意页面窃取。
修复建议
升级至 41.10.6、42.9.2、43.4.1 或 44.0.0-beta.5 及更高版本;临时缓解可避免在同一会话中加载不受信任内容,或按设计为相关 scheme 启用 corsEnabled。
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, responses served through protocol.registerFileProtocol or protocol.registerHttpProtocol for a custom scheme registered with supportFetchAPI enabled but corsEnabled disabled could remain script-readable across origins. This residual issue completes the remediation for CVE-2026-70604. Applications are affected only when they expose such a scheme and load untrusted content in the same session. Schemes intentionally registered with corsEnabled enabled remain cross-origin readable by design. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.