Feed/CVE-2026-70608
CVE-2026-70608HIGHCVSS 7.2

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

Published Aug 5, 2026·Updated Aug 5, 2026

NVD Description

### Impact A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that embed untrusted content in sandboxed iframes and rely on the absence of `allow-popups` to prevent window creation are affected. Apps that deny window creation in `setWindowOpenHandler`, or that do not embed untrusted content in sandboxed iframes, are not affected. ### Workarounds Return `{ action: 'deny' }` from `setWindowOpenHandler` for any content you do not trust, rather than relying on the iframe sandbox alone. ### Fixed Versions * `42.0.1` * `41.10.3` * `39.8.10` ### For more information If you have any questions or comments about this advisory, email Electron at [security@electronjs.org](mailto:security@electronjs.org)

Affected Packages (1)

electronNPM
From 42.0.0-alpha.1
Fixed in 42.0.1

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free