CVE-2026-102674: Electron: Windows opened from a sandboxed top-level document do not inherit its sandbox restrictions
### Impact Windows opened from a sandboxed top-level document did not inherit that document's HTML `sandbox` restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes. Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with `setWindowOpenHandler` are not affected. ### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for windows opened by untrusted content. ### Fixed Versions * `44.0.0-beta.5` * `43.4.1` * `42.9.2` * `41.10.6` ### For more information If you have any questions or comments about this advisory, email us at [[email protected]](mailto:[email protected])
Recommended action
Recommended action
Upgrade affected packages to a patched version: electron 41.10.6, electron 42.9.2, electron 43.4.1, electron 44.0.0-beta.5.
Technical details
- Vendor
- Not specified
- Product
- electron
- Exploitation
- none known
- Evidence
- official
Evidence and sources
This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source