Sceawere
Vulnerability Detail
CVE-2026-102673UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Electron Sandbox Escape via Popups
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.2
- Creation Date
- 8h ago
- Vendor
- electron
- Product
- electron
- Attack Type
- CWE-346: Origin Validation Error
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.2",
"pubDate": "2026-09-29T17:17:07.487Z",
"pubdate": "2026-09-29T17:17:07.487Z",
"executiveSummary": "This vulnerability is an improper restriction of sandbox properties in Electron, which allows a sandboxed iframe to bypass security constraints when spawning popups. The issue affects Electron versions prior to 41.10.4, 42.5.2, and 43.0.0.\nThe vulnerability allows an untrusted iframe, configured with 'allow-scripts' and 'allow-popups', to launch a new browser window that fails to inherit the necessary security sandbox restrictions from the parent iframe. Consequently, the spawned popup operates with the full origin and capabilities of the main embedding application.\nThis represents a significant security risk, as it allows for cross-origin attacks where untrusted content can access sensitive information, including cookies, local storage, and same-origin scripting APIs, thereby violating the Same-Origin Policy (SOP).\nExploitation requires an application to host untrusted content within a sandboxed iframe. Attackers can leverage standard navigation patterns, such as 'target=\"_blank\"' or middle-click events, to trigger the vulnerability. The impact is a complete bypass of the intended application sandbox for the popup window.",
"technicalDetails": "The root cause of this vulnerability lies in the 'OpenURLFromTab' navigation path within Electron, which fails to propagate HTML sandbox attributes to popups spawned from within a sandboxed iframe context.\nWhen a sandboxed iframe uses the 'allow-scripts' and 'allow-popups' sandbox directives, it is permitted to create new windows. However, due to the flaw in the navigation path, the resulting popup does not inherit the security limitations of the parent iframe. Instead, it defaults to the full privileges of the main Electron application origin.\nThe attack flow proceeds as follows: 1) An attacker injects or hosts malicious content inside a sandboxed iframe within the Electron application. 2) The iframe is configured with the 'allow-scripts' and 'allow-popups' attributes. 3) The malicious content triggers a popup navigation through a 'target=\"_blank\"' anchor tag or a middle-click event. 4) Electron's 'OpenURLFromTab' process handles the request but neglects to apply the sandbox constraints to the new window instance. 5) The resulting popup inherits the parent application's origin, bypassing the security restrictions that should have been enforced.\nThe post-exploitation impact allows the attacker to execute arbitrary scripts in the context of the main application's origin. This provides the attacker full access to the application's cookies, indexedDB, localStorage, and session storage. Furthermore, the attacker can interact with other same-origin resources, effectively breaking the isolation between untrusted third-party content and the trusted host application.\nThis vulnerability is limited to applications that host untrusted content within sandboxed iframes. If the application does not utilize untrusted iframes, it remains unaffected by this specific vector. The exploitation does not require prior authentication or elevated privileges, provided the attacker can successfully render the malicious iframe within the target application."
}