Electron · Electron · CVE-2026-102673
**Name of the Vulnerable Software and Affected Versions**
Electron versions prior to 41.10.4
Electron versions prior to 42.5.2
Electron versions prior to 43.0.0
**Description**
Popups opened from a sandboxed iframe via the OpenURLFromTab navigation path, such as links using `target=" blank"` or middle-clicks, fail to inherit the HTML sandbox restrictions. An untrusted iframe configured with `allow-scripts` and `allow-popups` can open a popup with the full origin of the embedding application. This allows the popup to access the origin's cookies, storage, and same-origin scripting capabilities. This issue only affects applications that embed untrusted content in sandboxed iframes.
**Recommendations**
Update to version 41.10.4.
Update to version 42.5.2.
Update to version 43.0.0.
Use `setWindowOpenHandler` on the parent `WebContents` to deny or constrain popups opened from sandboxed frames.
Avoid applying `allow-popups` to sandboxed iframes that render untrusted content.