top of page
perceptive_background_267k.jpg

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed ifram…

Published:

4 August 2026 at 22:00:00

Alert date:

5 August 2026 at 19:00:37

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies

A security vulnerability in the Electron framework allows sandboxed iframes without the allow-popups keyword to bypass popup restrictions and open new windows or trigger setWindowOpenHandler without user interaction. The flaw exists because new-window navigations taking the OpenURL path did not properly enforce iframe sandbox popup restrictions. Applications embedding untrusted content in sandboxed iframes that rely on the absence of allow-popups to prevent window creation are affected. Apps that explicitly deny window creation in setWindowOpenHandler or do not embed untrusted content in sandboxed iframes are not impacted. The vulnerability affects Electron versions prior to 39.8.10, 41.10.3, and 42.0.1. Fixes have been released in versions 39.8.10, 41.10.3, and 42.0.1. Multiple commits and pull requests on GitHub address the issue across the affected version branches.

Technical details

Mitigation steps:

Affected products:

Electron Framework
Electron 39.x prior to 39.8.10
Electron 41.x prior to 41.10.3
Electron 42.x prior to 42.0.1

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page