MEDIUM 6.7 GitHub

CVE-2026-102672

Electron: Local race condition in Squirrel.Mac update installation on macOS

### Impact On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine. Apps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, a

Affected Products

References

Published: 2026-09-29 · Source: GitHub · Feed updated: 2026-09-30
This medium severity vulnerability with a CVSS score of 6.7 was published on 2026-09-29 via GitHub. Affected: npm/electron < 39.8.10, npm/electron >= 40.0.0-alpha.1, < 41.10.5, npm/electron >= 42.0.0-alpha.1, < 42.0.0-beta.2.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.