Electron: File and HTTP protocol handlers allow cross-origin reads without corsEnabled (CVE-2026-102675) | HOL Guard CVE