
Session cache isolation bypass in Electron: ProtocolResponse.url without an explicit session fell through to defaultSession’s cache, crossing isolated partitions (CVE-2026-70606). Fixed via coordinated disclosure. https://github.com/advisories/GHSA-r4w5-6pfg-jxp5 #Electron #BugBounty #CVE
Post summary
The advisory reveals a session cache isolation bypass in Electron (CVE-2026-70606) and notes it has been fixed via coordinated disclosure, with technical details and a link to the GitHub advisory.
