


Perceptive Security
SOC/SIEM Consultancy

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed ifram…
Published:
4 August 2026 at 22:00:00
Alert date:
5 August 2026 at 19:00:37
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies
A security vulnerability in the Electron framework allows sandboxed iframes without the allow-popups keyword to bypass popup restrictions and open new windows or trigger setWindowOpenHandler without user interaction. The flaw exists because new-window navigations taking the OpenURL path did not properly enforce iframe sandbox popup restrictions. Applications embedding untrusted content in sandboxed iframes that rely on the absence of allow-popups to prevent window creation are affected. Apps that explicitly deny window creation in setWindowOpenHandler or do not embed untrusted content in sandboxed iframes are not impacted. The vulnerability affects Electron versions prior to 39.8.10, 41.10.3, and 42.0.1. Fixes have been released in versions 39.8.10, 41.10.3, and 42.0.1. Multiple commits and pull requests on GitHub address the issue across the affected version branches.
Technical details
Mitigation steps:
Affected products:
Electron Framework
Electron 39.x prior to 39.8.10
Electron 41.x prior to 41.10.3
Electron 42.x prior to 42.0.1
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-70608
https://github.com/electron/electron/commit/3ff23c52ab364a0afc6ab5bd7851291d3159de57
https://github.com/electron/electron/commit/57cbe329c4ae8aab5ac5ebdcb588adc9a11de0d3
https://github.com/electron/electron/commit/68cf8b7d9122260f6b534a69a82c701a56cf159f
https://github.com/electron/electron/pull/51437
https://github.com/electron/electron/pull/51438
https://github.com/electron/electron/pull/51439
https://github.com/electron/electron/releases/tag/v39.8.10
https://github.com/electron/electron/releases/tag/v41.10.3
https://github.com/electron/electron/releases/tag/v42.0.1
https://github.com/electron/electron/security/advisories/GHSA-9f4c-93c8-jc8g
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
