If the Electron app never shows untrusted HTML with Javascript enabled, then it's not an issue. Generally, only Electron apps with arbitrary web browsing functionality would do that.
Do most Electron apps make use of CSP? eg: is it an inherent part of the build process, or is it something that the developer needs to explicitly add?
Which is a massive security issue in itself--Electron documentation even warns you about this.
So attacker would still need to have some javascript loaded somewhere for it to work. If electron app displays user-generated content, XSS can help run a javascript payload, however.