CVE-2026-102673: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab

Published Sep 29, 2026
·
Updated

Impact

Popups opened from a sandboxed iframe through a link (for example target="blank" or a middle-click) did not inherit the iframe's HTML sandbox restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting.

Apps are only affected if they embed untrusted content in iframes sandboxed with allow-scripts allow-popups. Apps that do not embed untrusted content in sandboxed iframes are not affected.

Workarounds

Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.

Fixed Versions

43.0.0 42.5.2 41.10.4

For more information

If you have any questions or comments about this advisory, email us at security@electronjs.org

Other sources

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

— MITRE

Affected Software

4 affected componentsFixes available
Electron Electron<41.10.4, >=42.0.0<42.5.2, <43.0.0
npm/electron>=43.0.0-alpha.1<43.0.0
43.0.0
npm/electron>=42.0.0-alpha.1<42.5.2
42.5.2
npm/electron<41.10.4
41.10.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 43.0.0
  2. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 42.5.2
  3. Upgrade

    Upgrade npm/electron to a version that resolves this vulnerability.

    Fixed in 41.10.4
  4. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 41.10.4
  5. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 42.5.2
  6. Upgrade

    Upgrade Electron to a version that resolves this vulnerability.

    Fixed in 43.0.0
  7. Configuration

    Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames, or do not apply allow-popups to sandboxed iframes that render untrusted content.

    Electron setWindowOpenHandler / iframe allow-popups = Deny or constrain popups; or omit allow-popups

Event History

Sep 29, 2026
CVE Published
via MITRE·04:38 PM
Data Sourced
via MITRE·04:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:05 PM
Data Sourced
via GitHub·06:05 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

Which applications are exposed to this issue?

Applications are affected only if they embed untrusted content in sandboxed iframes and permit that content to use scripts and open popups with the allow-scripts allow-popups configuration. Applications that do not embed untrusted content in sandboxed iframes are not affected.

2

What must an attacker-controlled iframe do to exploit the issue?

The iframe must open a popup through Electron's OpenURLFromTab navigation path, such as by using a link with target="_blank" or through a middle-click. The resulting popup can receive the embedding application's full origin rather than inherited HTML sandbox restrictions.

3

What could the attacker access through the improperly sandboxed popup?

The popup can expose the embedding application's origin cookies, storage, and same-origin scripting capabilities to the untrusted content.

4

Which Electron releases contain fixes?

The issue is fixed in Electron versions 41.10.4, 42.5.2, and 43.0.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203