THREAT OPS › Threat News › [GHSA] GHSA-v93f-fgjr-hjrj (medium) — Electron: window.open features string controls some window options considered privileged
[GHSA] GHSA-v93f-fgjr-hjrj (medium) — Electron: window.open features string controls some window options considered privileged
GHSA-v93f-fgjr-hjrj Severity: medium CVE: CVE-2026-70607
Electron: window.open features string controls some window options considered privileged
### Impact Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause t
Indicators of compromise
- CVE-2026-70607cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-v93f-fgjr-hjrj