Electron, HTML Sandbox Restriction Bypass, CVE-2026-102673 (High) -DC-Sep2026-2625

Listen to this Post

CVE-2026-102673 is a high-severity vulnerability in Electron, a framework for building cross-platform desktop applications using JavaScript, HTML, and CSS. The flaw resides in how Electron handles popups opened through its OpenURLFromTab navigation path, which is triggered by link dispositions such as target=”_blank” or a middle-click. The core issue is that when a popup is opened from a sandboxed iframe via this specific navigation path, the new window does not inherit the sandbox restrictions of the initiating iframe. The OpenURLFromTab path is a Chromium-level navigation mechanism used by Electron to handle requests to open URLs in new windows or tabs. In this path, the code relied on params.frame_tree_node_id to identify the initiating frame for applying sandbox flags. However, this identifier only points to the target frame and is unset for non-CURRENT_TAB dispositions, meaning the existing sandbox check was never executed. As a result, an iframe sandboxed with the allow-scripts and allow-popups attributes could open a popup that received the embedding application’s full origin authority instead of inheriting the sandbox. This means the popup gains access to the parent application’s cookies, local storage, and same-origin scripting capabilities, effectively escaping the sandbox. The vulnerability is classified as CWE-346 (Origin Validation Error) and CWE-693 (Protection Mechanism Failure). Applications that embed untrusted content in iframes sandboxed with allow-scripts and allow-popups are affected. Applications that do not embed untrusted content in sandboxed iframes are not affected. The issue was fixed in Electron versions 41.10.4, 42.5.2, and 43.0.0. The fix involves resolving the initiating frame from the OpenURLParams source render frame, reading its active sandboxing flag set, and passing those flags through the -new-window event so the new window’s WebContents is created with the correct sandbox flags, unless allow-popups-to-escape-sandbox is set.

DailyCVE Form:

Platform: Electron
Version: < 41.10.4, 42.5.2, 43.0.0
Vulnerability: Sandbox bypass
Severity: High
date: Aug 28, 2026

Prediction: Patch expected Sep 29, 2026

What Undercode Say:

Bash Commands:

Check installed Electron version
npm list electron
Install a patched version
npm install [email protected]
npm install [email protected]
npm install [email protected]

Code:

// Workaround: deny popups from sandboxed frames
mainWindow.webContents.setWindowOpenHandler(({ url }) => {
return { action: 'deny' };
});
<!-- Vulnerable iframe configuration -->

<iframe sandbox="allow-scripts allow-popups" src="untrusted.html"></iframe>

<!-- Mitigated iframe configuration -->

<iframe sandbox="allow-scripts" src="untrusted.html"></iframe>

Exploit: (Educational Purposes!)

An attacker embeds an iframe with the sandbox attribute set to allow-scripts allow-popups, loading untrusted content. The content uses a link with target=”_blank” or a middle-click event to open a popup. Due to the OpenURLFromTab path not applying the iframe’s sandbox flags, the popup opens with the embedding application’s full origin. The attacker’s script in the popup can then read document.cookie, access localStorage, and make same-origin requests on behalf of the application.

Protection: from this CVE

Update Electron to version 41.10.4, 42.5.2, or 43.0.0. Use setWindowOpenHandler on the parent WebContents to deny or constrain popups opened from sandboxed frames. Do not apply the allow-popups attribute to sandboxed iframes that render untrusted content.

Impact:

Popups opened from a sandboxed iframe through a link did not inherit the iframe’s HTML sandbox restrictions. Content meant to run sandboxed could open a popup with the embedding app’s full origin, gaining access to that origin’s cookies, storage, and same-origin scripting.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top