Electron desktop trust-boundary review
Anonymised pattern: Electron desktop product where preload and IPC trust boundaries decide whether renderer compromise becomes local privilege or data access.
At a glance
Context / challenge
A product team shipping an Electron client needed a desktop-focused review before enterprise rollout. Primary questions: which trust boundaries exist between renderer, preload and main; whether IPC exposure allows sensitive actions; and how update and packaging choices affect local risk.
This pattern pairs with our desktop / Electron penetration testing service and the public Electron research series.
Engagement shape
Typical shape: desktop build in scope (packaged app + relevant update channel), threat model workshop, then targeted testing of preload bridges, IPC handlers, local storage of secrets/tokens, and update integrity assumptions. Web views that load remote content get special attention.
Approach
Discover
Threat-model renderer/preload/main; inventory IPC and update surfaces.
Validate
Test trust-boundary classes against the packaged build under RoE.
Prove
Evidence privileged actions reachable across boundaries — private report holds detail.
Remediate
Narrow bridges, harden handlers and update integrity, reduce secret sprawl.
Retest
Re-check priority trust-boundary classes on the fixed build.
Interactive steps — content remains fully readable without JavaScript.
Finding classes (illustrative)
Illustrative finding classes: over-broad preload exposure; IPC handlers that trust renderer input for privileged actions; insecure navigation or open redirects into privileged contexts; weak update verification; sensitive tokens stored with insufficient protection; node integration or sandbox misconfiguration classes.
Public pages stay at class level — detailed reproduction belongs in the private report under RoE.
Outcomes and remediation pattern
Engineering typically narrows preload APIs, adds server-side style authorisation in main-process handlers, hardens update verification and reduces secret sprawl on disk. Retest focuses on the trust-boundary classes agreed as priority.
Deep dives: IPC/preload bridge abuse, common misconfigurations, ASAR / updates / local privilege.
Lessons for buyers
- Treat Electron as a privileged desktop host, not “just a website wrapper.”
- Require IPC and preload review in the RFQ — not only OWASP Web labels.
- Link desktop findings to any cloud session tokens the client holds.
- Use the research series to align vocabulary with your engineering team.
Related patterns & research
- Desktop / Electron PT
- Electron security deep dive
- Electron engagement checklist
- SaaS isolation pattern (if the client holds tenant context)
Want this engagement shape scoped for you?
Share constraints and success criteria — PocForge will propose a human-led plan with proof and retest.
