{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aelectronjselectron/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-102673"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Electron (\u003c 41.10.4, \u003e= 42.0.0-alpha.1 \u003c 42.5.2, \u003e= 43.0.0-alpha.1 \u003c 43.0.0)","Electron (\u003c 41.10.6)","Electron (\u003e= 42.0.0-alpha.1, \u003c 42.9.2)","Electron (\u003e= 43.0.0-alpha.1, \u003c 43.4.1)","Electron (\u003e= 44.0.0-alpha.1, \u003c 44.0.0-beta.5)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","sandbox-bypass","web-application","electron","sandbox-escape"],"_cs_type":"advisory","_cs_vendors":["Electron"],"content_html":"\u003cp\u003eElectron versions prior to 41.10.4, 42.5.2, and 43.0.0 contain a security flaw where popups initiated from a sandboxed iframe via OpenURLFromTab fail to inherit the necessary HTML sandbox attributes. When an application embeds untrusted content within an iframe using the 'allow-scripts' and 'allow-popups' sandbox permissions, a popup window triggered by that content (e.g., via target=\u0026quot;_blank\u0026quot; or middle-click) defaults to the host application's full origin. This failure effectively strips the isolation meant to protect the application, granting the untrusted content access to the host's cookies, local storage, and the ability to execute same-origin scripts. This vulnerability poses a significant risk to Electron-based applications that render third-party or untrusted web content in sandboxed environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows untrusted code to break out of its restricted iframe environment and gain the privilege level of the parent application. This can lead to unauthorized data access, such as reading authentication cookies or local storage, and execution of scripts within the application's origin, which may result in data exfiltration or unauthorized actions performed on behalf of the user.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade applications utilizing Electron to version 41.10.4, 42.5.2, 43.0.0, or later to incorporate the patch for CVE-2026-102673.\u003c/li\u003e\n\u003cli\u003eImplement a 'setWindowOpenHandler' within the parent 'WebContents' to explicitly deny or constrain popup windows initiated from sandboxed frames.\u003c/li\u003e\n\u003cli\u003eEvaluate current iframe implementations and, where possible, remove 'allow-popups' from sandboxed iframes that process untrusted content until the application is upgraded.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-30T04:19:32Z","date_published":"2026-09-29T22:18:52Z","id":"https://feed.craftedsignal.io/briefs/2026-09-electron-sandbox-bypass/","summary":"A vulnerability in Electron prevents popups opened from sandboxed iframes from inheriting security restrictions, allowing potentially malicious content to access the embedding application's full origin.","title":"Electron Sandbox Restriction Bypass via Popups","url":"https://feed.craftedsignal.io/briefs/2026-09-electron-sandbox-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:electronjs:electron:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}