OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-102673

HIGH · CVSS 8.2 EPSS 0.15% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Electron versions prior to 41.10.4, 42.5.2, and 43.0.0 are vulnerable due to a flaw in how popups are handled from sandboxed iframes, allowing untrusted content to bypass HTML sandbox restrictions and potentially access sensitive data from the embedding application's origin. This could lead to unauthorized access to cookies, storage, and scripting capabilities, posing a significant security risk for applications that utilize untrusted iframes. Developers and organizations using Electron for their desktop applications should prioritize upgrading to the patched versions to mitigate this vulnerability.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-102673
Severity
HIGH
CVSS
8.2
EPSS
0.15%
Java

Original NVD Description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.