HIGH 7.2 npm

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

GHSA-9f4c-93c8-jc8g · CVE-2026-70608

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

A sandboxed iframe without the allow-popups keyword could still open a new window (or trigger setWindowOpenHandler) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction.

Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected. Apps that deny window creation in setWindowOpenHandler, or that do not embed untrusted content in sandboxed iframes, are not affected.

Workarounds

Return { action: 'deny' } from setWindowOpenHandler for any content you do not trust, rather than relying on the iframe sandbox alone.

Fixed Versions

  • 42.0.1
  • 41.10.3
  • 39.8.10

For more information

If you have any questions or comments about this advisory, email Electron at security@electronjs.org

Ready to move

Start Securing

Free, no credit card | First findings in minutes