CVE-2026-102673

LOWCVSS 8.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked 1d ago at 1 mentions (2026-09-29); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-09-29: 1Mentions · 2026-09-30: 109-2909-30
Referenced assets2 URLs
Full discourse2 posts
  • Daily CyberSecurity@Daily_CyberSec

    Five high-severity Electron vulnerabilities, including CVE-2026-102676, CVE-2026-102673 and CVE-2026-102674, weaken sandbox isolation. Update Electron now. #Electron #ElectronJS #CVE2026102676 #AppSecurity #Sandbox #JavaScript #DesktopApps #PatchNow https://securityonline.info/electron-vulnerabilities-sandbox-bypass/

    01000262
    13.0K followersView on X
  • DailyCVE@dailycve

    🔴 Electron, #HTML Sandbox Restriction Bypass, #CVE-2026-102673 (High) -DC-Sep2026-2625 https://dailycve.com/electron-html-sandbox-restriction-bypass-cve-2026-102673-high-dc-sep2026-2625/

    0000020
    238 followersView on X

Explore more