Electron: ProtocolResponse.url reuses the default session cache instead of the registering session (CVE-2026-70606) | HOL Guard CVE