CVE-2026-102673: Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
### Impact Popups opened from a sandboxed iframe through a link (for example `target="_blank"` or a middle-click) did not inherit the iframe's HTML `sandbox` restrictions. Content that was meant to run sandboxed could open a popup with the embedding app's full origin, gaining access to that origin's cookies, storage, and same-origin scripting. Apps are only affected if they embed untrusted content in iframes sandboxed with `allow-scripts allow-popups`. Apps that do not embed untrusted content in sandboxed iframes are not affected. ### Workarounds Use `setWindowOpenHandler` on the parent `WebContents` to deny or constrain popups opened from sandboxed frames, or do not apply `allow-popups` to sandboxed iframes that render untrusted content. ### Fixed Versions * `43.0.0` * `42.5.2` * `41.10.4` ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected])
Recommended action
Recommended action
Upgrade affected packages to a patched version: electron 41.10.4, electron 42.5.2, electron 43.0.0.
Technical details
- Vendor
- Not specified
- Product
- electron
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source