THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-9f4c-93c8-jc8g (high) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

[GHSA] GHSA-9f4c-93c8-jc8g (high) — Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

medgithub_advisoriesPublished 2026-08-05

GHSA-9f4c-93c8-jc8g Severity: high CVE: CVE-2026-70608

Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path

### Impact A sandboxed iframe without the `allow-popups` keyword could still open a new window (or trigger `setWindowOpenHandler`) with no user interaction, because new-window navigations taking the OpenURL path did not apply the iframe sandbox

Indicators of compromise

Original source: https://github.com/advisories/GHSA-9f4c-93c8-jc8g