VYPR
High severityNVD Advisory· Published Aug 5, 2026

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

CVE-2026-70608

Description

Impact

A sandboxed iframe without the allow-popups keyword could still open a new window (or trigger setWindowOpenHandler) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.

Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected. Apps that deny window creation in setWindowOpenHandler, or that do not embed untrusted content in sandboxed iframes, are not affected.

Workarounds

Return { action: 'deny' } from setWindowOpenHandler for any content you do not trust, rather than relying on the iframe sandbox alone.

Fixed

Versions * 42.0.1 * 41.10.3 * 39.8.10

For more information

If you have any questions or comments about this advisory, email Electron at [email protected]

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
electronnpm
>= 42.0.0-alpha.1, < 42.0.142.0.1
electronnpm
>= 40.0.0-alpha.1, < 41.10.341.10.3
electronnpm
< 39.8.1039.8.10

Affected products

1

Patches

Vulnerability mechanics

References

11

News mentions

0

No linked articles in our index yet.