PT-2026-102684 · Electron · Electron

·

CVE-2026-102673

·

Published

2026-09-29

·

Updated

2026-09-30

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Electron versions prior to 41.10.4 Electron versions prior to 42.5.2 Electron versions prior to 43.0.0
Description Popups opened from a sandboxed iframe via the OpenURLFromTab navigation path, such as links using target=" blank" or middle-clicks, fail to inherit the HTML sandbox restrictions. An untrusted iframe configured with allow-scripts and allow-popups can open a popup with the full origin of the embedding application. This allows the popup to access the origin's cookies, storage, and same-origin scripting capabilities. This issue only affects applications that embed untrusted content in sandboxed iframes.
Recommendations Update to version 41.10.4. Update to version 42.5.2. Update to version 43.0.0. Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames. Avoid applying allow-popups to sandboxed iframes that render untrusted content.

Exploit

Fix

Protection Mechanism Failure

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102673
GHSA-HQ2X-R82H-9WJ4

Affected Products

Electron