Electron drops inherited HTML sandbox restrictions for popups opened through OpenURLFromTab
Published Sep 29, 2026
8.2
HIGHCVSS 3.1
EPSS 0.15%
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.
Affected products
-
- Version < 41.10.4StatusaffectedConstraints-
- Version >= 42.0.0-alpha.1, < 42.5.2StatusaffectedConstraints-
- Version >= 43.0.0-alpha.1, < 43.0.0StatusaffectedConstraints-
- Version
No data.
No data.
Red Hat Build of Podman Desktop
rh-podman-desktop
Affected
Red Hat Enterprise Linux 10
podman-desktop
Affected
Red Hat Enterprise Linux 10
rh-podman-desktop
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | podman-desktop | Affected | n/a |
| Red Hat Enterprise Linux 10 | rh-podman-desktop | Affected | n/a |
electron
npm
Introduced 0 Fixed 41.10.4electron
npm
Introduced 42.0.0-alpha.1 Fixed 42.5.2electron
npm
Introduced 43.0.0-alpha.1 Fixed 43.0.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | electron | 0 | 41.10.4 |
| npm | electron | 42.0.0-alpha.1 | 42.5.2 |
| npm | electron | 43.0.0-alpha.1 | 43.0.0 |
Remediation
Red Hat statement
A flaw was found in Electron where popup windows opened from a sandboxed iframe via navigation actions (such as target="_blank" links or middle-clicks) fail to inherit the iframe's sandbox security restrictions. An attacker controlling untrusted content in a sandboxed iframe configured with allow-scripts and allow-popups can exploit this issue to open a popup running under the embedding application's full origin, exposing sensitive data such as cookies, storage, and same-origin scripting capabilities.
Red Hat mitigation
Avoid embedding untrusted web content inside sandboxed iframes configured with allow-popups, or intercept new window navigation requests using setWindowOpenHandler to validate and deny unexpected popup requests.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (13)
- https://access.redhat.com/security/cve/CVE-2026-102673 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2543311 Issue Tracking
- https://github.com/advisories/GHSA-hq2x-r82h-9wj4 Advisory
- https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba x_refsource_MISC
- https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69 x_refsource_MISC
- https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da x_refsource_MISC
- https://github.com/electron/electron/pull/52133 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v41.10.4 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v42.5.2 x_refsource_MISC
- https://github.com/electron/electron/releases/tag/v43.0.0 x_refsource_MISC
- https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4 x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2026-102673
- https://www.cve.org/CVERecord?id=CVE-2026-102673
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-102673 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2543311 | Issue Tracking | |
| https://github.com/advisories/GHSA-hq2x-r82h-9wj4 | Advisory | |
| https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba | x_refsource_MISC | |
| https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69 | x_refsource_MISC | |
| https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da | x_refsource_MISC | |
| https://github.com/electron/electron/pull/52133 | x_refsource_MISC | |
| https://github.com/electron/electron/releases/tag/v41.10.4 | x_refsource_MISC | |
| https://github.com/electron/electron/releases/tag/v42.5.2 | x_refsource_MISC | |
| https://github.com/electron/electron/releases/tag/v43.0.0 | x_refsource_MISC | |
| https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4 | x_refsource_CONFIRM | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-102673 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-102673 |
Change history (0)
No recorded changes yet.