THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-v93f-fgjr-hjrj (medium) — Electron: window.open features string controls some window options considered privileged

[GHSA] GHSA-v93f-fgjr-hjrj (medium) — Electron: window.open features string controls some window options considered privileged

medgithub_advisoriesPublished 2026-08-05

GHSA-v93f-fgjr-hjrj Severity: medium CVE: CVE-2026-70607

Electron: window.open features string controls some window options considered privileged

### Impact Some window options supplied by web content in the `window.open()` features string were applied to the new `BrowserWindow` without an allowlist. Untrusted content could set window options it should not control, including options that cause t

Indicators of compromise

Original source: https://github.com/advisories/GHSA-v93f-fgjr-hjrj