THREAT OPS › Threat News › [GHSA] GHSA-9f4c-93c8-jc8g (high) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
[GHSA] GHSA-9f4c-93c8-jc8g (high) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
GHSA-9f4c-93c8-jc8g Severity: high CVE: CVE-2026-70608
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path
### Impact A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox
Indicators of compromise
- CVE-2026-70608cve
- security@electronjs.orgemail
Original source: https://github.com/advisories/GHSA-9f4c-93c8-jc8g