CVE-2026-102673: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
Impact
Popups opened from a sandboxed iframe through a link (for example target="blank" or a middle-click) did not inherit the iframe's HTML sandbox restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.
Apps are only affected if they embed untrusted content in iframes sandboxed with allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.
Workarounds
Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.
Fixed Versions
43.0.0 42.5.2 41.10.4
For more information
If you have any questions or comments about this advisory, email us at security@electronjs.org
Other sources
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 43.0.0 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 42.5.2 - Upgrade
Upgrade
npm/electronto a version that resolves this vulnerability.Fixed in 41.10.4 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 41.10.4 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 42.5.2 - Upgrade
Upgrade
Electronto a version that resolves this vulnerability.Fixed in 43.0.0 - Configuration
Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.
Electron setWindowOpenHandler / iframe allow-popups = Deny or constrain popups; or omit allow-popups
Event History
Frequently Asked Questions
Which applications are exposed to this issue?
Applications are affected only if they embed untrusted content in sandboxed iframes and permit that content to use scripts and open popups with the allow-scripts allow-popups configuration. Applications that do not embed untrusted content in sandboxed iframes are not affected.
What must an attacker-controlled iframe do to exploit the issue?
The iframe must open a popup through Electron's OpenURLFromTab navigation path, such as by using a link with target="_blank" or through a middle-click. The resulting popup can receive the embedding application's full origin rather than inherited HTML sandbox restrictions.
What could the attacker access through the improperly sandboxed popup?
The popup can expose the embedding application's origin cookies, storage, and same-origin scripting capabilities to the untrusted content.
Which Electron releases contain fixes?
The issue is fixed in Electron versions 41.10.4, 42.5.2, and 43.0.0.