OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

CVE-2026-102673: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab

GitHub Advisories · officialPublished Sep 29, 2026Risk 37/100

### Impact Popups opened from a sandboxed iframe through a link (for example `target="_blank"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting. Apps are only affected if they embed untrusted content in iframes sandboxed with `allow-scripts allow-popups`. Apps that do not embed untrusted content in sandboxed iframes are not affected. ### Workarounds Use `setWindowOpenHandler` on the parent `WebContents` to deny or constrain popups opened from sandboxed frames, or do not apply `allow-popups` to sandboxed iframes that render untrusted content. ### Fixed Versions * `43.0.0` * `42.5.2` * `41.10.4` ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected])

Upgrade affected packages to a patched version: electron 41.10.4, electron 42.5.2, electron 43.0.0.

Vendor
Not specified
Product
electron
Exploitation
none known
Evidence
official
CVSS
8.2

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source