GHSA-9f4c-93c8-jc8gHighCVSS 7.2

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

Published
August 5, 2026
Last Modified
August 5, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A sandboxed iframe without the allow-popups keyword could still open a new window (or trigger setWindowOpenHandler) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.

Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected. Apps that deny window creation in setWindowOpenHandler, or that do not embed untrusted content in sandboxed iframes, are not affected.

Workarounds

Return { action: 'deny' } from setWindowOpenHandler for any content you do not trust, rather than relying on the iframe sandbox alone.

Fixed Versions

  • 42.0.1
  • 41.10.3
  • 39.8.10

For more information

If you have any questions or comments about this advisory, email Electron at [email protected]

🎯 Affected products3

  • npm/electron:>= 42.0.0-alpha.1, < 42.0.1
  • npm/electron:>= 40.0.0-alpha.1, < 41.10.3
  • npm/electron:< 39.8.10

🔗 References (11)