Sandboxed Document Vulnerability in Electron Framework
CVE-2026-102674
What is CVE-2026-102674?
The Electron framework allows the creation of cross-platform desktop applications using web technologies. A vulnerability existed in earlier versions of Electron, where windows opened from a sandboxed top-level document did not inherit the expected security restrictions of that document. This loophole enabled untrusted content in the sandboxed document to potentially open new windows with access to the full origin of the Electron application instead of being confined to the intended restricted origin. Applications that effectively manage popup behavior using setWindowOpenHandler were not affected by this issue. The flaw was addressed in specified newer versions of the framework.
Affected Version(s)
electron < 41.10.6 < 41.10.6
electron >= 42.0.0-alpha.1, < 42.9.2 < 42.0.0-alpha.1, 42.9.2
electron >= 43.0.0-alpha.1, < 43.4.1 < 43.0.0-alpha.1, 43.4.1
