Sceawere

Vulnerability Detail

CVE-2026-102674UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Electron Sandbox Escape Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.2
Creation Date
8h ago
Vendor
electron
Product
electron
Attack Type
CWE-266: Incorrect Privilege Assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5, windows opened from a sandboxed top-level document did not inherit that document's active HTML sandbox restrictions. Untrusted content in a sandboxed top-level document that was permitted to open popups could therefore create a window with the Electron application's full origin instead of the restricted origin intended by the sandbox. Applications that deny such popups with setWindowOpenHandler are not affected. This issue is fixed in versions 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.2",
  "pubDate": "2026-09-29T17:17:07.653Z",
  "pubdate": "2026-09-29T17:17:07.653Z",
  "executiveSummary": "This vulnerability is an improper sandbox restriction inheritance issue affecting Electron applications. The flaw allows sandboxed top-level documents to spawn new windows that fail to inherit the necessary security constraints, effectively enabling a sandbox escape.\nThe vulnerability allows untrusted content within a restricted context to bypass sandbox protections and inherit the full origin and privileges of the Electron application. An attacker capable of executing arbitrary JavaScript within a sandboxed renderer can potentially escalate their execution context to a more privileged state, bypassing intended origin restrictions.\nThe impact is significant as it undermines the fundamental security model of Electron's web-content isolation. Affected versions include all versions prior to 41.10.6, 42.9.2, 43.4.1, and 44.0.0-beta.5. Exploitation requires the attacker to successfully inject or host untrusted content within a sandboxed document that has the ability to trigger window openings.\nThis vulnerability poses a severe risk to application integrity and user data confidentiality, as it permits attackers to break out of the intended restrictive environment. Applications that proactively block all window opening operations via setWindowOpenHandler remain unaffected.",
  "technicalDetails": "The root cause of this vulnerability lies in the failure of the Electron framework to propagate active HTML sandbox attributes when a secondary window is spawned from a sandboxed top-level document. In a properly configured environment, windows opened by an iframe or a document with the 'sandbox' attribute should inherit the restricted security context of the parent, effectively limiting the new window's capabilities, origin, and access to privileged APIs.\nIn the affected Electron versions, the framework incorrectly assigns the main Electron application's full origin and capability set to the new window. Consequently, if a sandboxed document is permitted to execute 'window.open()', the resulting window is created without the constraints dictated by the original sandbox policy. This represents a breakdown in the security boundary between untrusted, sandboxed content and the privileged Electron main process or associated renderer contexts.\nThe attack flow follows this sequence: 1) The attacker injects malicious scripts into an Electron renderer process that is utilizing the sandbox feature. 2) The attacker leverages the sandboxed context to invoke window.open(). 3) Because of the flaw, the new window is initialized with the host application's origin rather than the restricted sandbox origin. 4) The attacker-controlled window then operates with elevated privileges, enabling it to perform actions normally restricted by the sandbox, such as cross-origin requests, accessing sensitive browser APIs, or interacting with the host OS in ways that were intended to be forbidden.\nThe component responsible for this behavior is the window management logic within Electron that interfaces with the Chromium rendering engine. This vulnerability is primarily exploitable by any actor who can cause the application to load or execute malicious content, such as through cross-site scripting (XSS) or the loading of untrusted remote resources. Successful exploitation leads to a complete bypass of the renderer's security policy, allowing the attacker to perform privileged operations or access data that the sandboxed document should have been isolated from. The issue is persistent until the framework is updated to ensure that sandbox flags are correctly applied to the BrowserWindow instantiation process regardless of the initiator's context."
}
CVE-2026-102674: Electron Sandbox Escape Vulnerability (HIGH Severity, CVSS: 8.2) | Sceawere