天下漏洞,尽知其名
HIGH

CVE-2026-102677 Electron 沙箱预加载缓存注入漏洞

影响攻击者可在预加载上下文中执行任意代码,提升权限

AI 研判

Electron 的沙箱预加载代码缓存未校验缓存条目与所服务预加载脚本是否匹配。被攻陷的渲染进程可写入攻击者控制的缓存数据,使 Electron 在后续加载中复用,从而在权限更高的预加载上下文中执行渲染进程的代码。该问题影响加载不受信任内容的应用。

影响范围

Electron

Electron 42.3.3 起至 42.10.0、43.5.0、44.0.0-beta.6 之前的版本。

漏洞详情

漏洞类型为代码缓存注入导致的权限提升。成因是沙箱预加载代码缓存缺少缓存条目与预加载脚本的绑定校验,渲染进程可污染缓存。利用方式是先攻陷渲染进程写入恶意缓存,待后续加载时被复用,从而在预加载上下文执行代码。

利用条件与风险

利用前提是应用加载不受信任内容且渲染进程已被攻陷,实战中可导致沙箱逃逸级别的权限提升,风险较高。

修复建议

升级至 Electron 42.10.0、43.5.0 或 44.0.0-beta.6 及以上版本;临时缓解措施暂无公开信息。

原始情报

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. From 42.3.3 until 42.10.0, 43.5.0, and 44.0.0-beta.6, Electron’s sandboxed preload code cache did not verify that a cached entry matched the preload it was served for. A compromised renderer could write attacker-controlled cache data and cause Electron to reuse it for a later load, executing the renderer’s code in the more privileged preload context. The issue affects applications that load untrusted content. This issue is fixed in versions 42.10.0, 43.5.0, and 44.0.0-beta.6.