CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

GHSA-9f4c-93c8-jc8g: Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

highCVSS 7.2CVE-2026-70608
Impact A sandboxed iframe without the allow-popups keyword could still open a new window (or trigger setWindowOpenHandler) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected. Apps that deny window creation in setWindowOpenHandler, or that do not embed untrusted content in sandboxed iframes, are not affected. Workarounds Return { action: 'deny' } from setWindowOpenHandler for any content you do not trust, rather than relying on the iframe sandbox alone. Fixed Versions - 42.0.1 - 41.10.3 - 39.8.10 For more information If you have any questions or comments about this advisory, email Electron at security@electronjs.org

Details

Source
GitHub Security Advisories (INTL · database · site)
Severity
high — CVSS 7.2
Published
2026-08-05
Last updated
2026-08-05
Exploitation
Not in CISA KEV at last sync

Original advisory: https://github.com/advisories/GHSA-9f4c-93c8-jc8g

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-70608coverage & exploitation statusNVD · CVE.org

More from GitHub Security Advisories