THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-p2rr-rvmm-c5fp (medium) — Electron: Sandboxed iframes can launch external protocol handlers

[GHSA] GHSA-p2rr-rvmm-c5fp (medium) — Electron: Sandboxed iframes can launch external protocol handlers

medgithub_advisoriesPublished 2026-08-05

GHSA-p2rr-rvmm-c5fp Severity: medium CVE: CVE-2026-70612

Electron: Sandboxed iframes can launch external protocol handlers

### Impact Requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame's sandbox state was also not made available to the app

Indicators of compromise

Original source: https://github.com/advisories/GHSA-p2rr-rvmm-c5fp