MEDIUM 6.7 GitHub
CVE-2026-102672
Electron: Local race condition in Squirrel.Mac update installation on macOS
### Impact
On macOS, Electron bundles the Squirrel.Mac auto-update framework, whose privileged `ShipIt` helper performs the final step of an update as root. A local attacker could cause that helper to overwrite a different application's files, as root, instead of the app that started the update. Exploitation requires local access to the machine.
Apps are only affected on macOS if they ship Squirrel.Mac-based auto-updates. Apps on other platforms, or that do not use Squirrel.Mac auto-updates, a
Affected Products
- npm/electron < 39.8.10
- npm/electron >= 40.0.0-alpha.1, < 41.10.5
- npm/electron >= 42.0.0-alpha.1, < 42.0.0-beta.2
References
- https://github.com/advisories/GHSA-vv43-5jgx-7qv8
- https://github.com/electron/electron/security/advisories/GHSA-vv43-5jgx-7qv8
- https://github.com/electron/electron/pull/50745
- https://github.com/electron/electron/commit/01faabfc250801a980fc94d64608046c67fc1cd9
This medium severity vulnerability with a CVSS score of 6.7 was published on 2026-09-29 via GitHub. Affected: npm/electron < 39.8.10, npm/electron >= 40.0.0-alpha.1, < 41.10.5, npm/electron >= 42.0.0-alpha.1, < 42.0.0-beta.2.
vulnfeed aggregates 10239 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.