天下漏洞,尽知其名
HIGH

CVE-2026-102676 Electron webview 权限提升漏洞

影响不可信 webview 内容可创建具备 Node 权限的 Worker,导致权限提升

AI 研判

Electron 是使用 JavaScript、HTML 和 CSS 编写跨平台桌面应用的框架。在 41.10.6、42.9.2、43.4.1 和 44.0.0-beta.5 之前的版本中,<webview> 访客内容即使宿主未开启 Node.js 集成,也能为其 Web Worker 启用 nodeIntegrationInWorker,从而获得超出宿主授予的权限。未启用 <webview> 标签或保持宿主沙箱的应用不受影响。

影响范围

Electron

Electron 41.10.6、42.9.2、43.4.1、44.0.0-beta.5 之前的版本;仅影响启用 <webview> 标签且宿主未沙箱化的应用。

漏洞详情

该漏洞属于权限提升/沙箱绕过类问题。成因是 <webview> 访客可自行设置 nodeIntegrationInWorker,使 Web Worker 获得 Node.js 能力,而宿主原本已禁用 Node 集成。攻击者通过不可信的 webview 内容即可创建高权限 Worker,进而访问文件系统或执行系统命令。

利用条件与风险

利用前提是应用启用了 <webview> 标签且宿主未启用沙箱;若满足条件,不可信远程内容可提升权限,实战风险较高。

修复建议

升级到 41.10.6、42.9.2、43.4.1 或 44.0.0-beta.5 及更高版本;临时缓解措施为禁用 <webview> 标签或保持宿主沙箱化。

原始情报

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, an Electron guest could enable nodeIntegrationInWorker for its Web Workers even when the unsandboxed embedder had Node.js integration disabled, allowing untrusted guest content to create a Node-enabled worker with more privilege than the embedder granted. Applications that do not enable the tag or that keep the embedder sandboxed are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.