Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a sandboxed iframe could cause an OS-registered external application to be launched. The frame sandbox state was also not made available to the app permission handlers, affecting apps that render untrusted content in sandboxed iframes and grant the openExternal permission by default when no setPermissionRequestHandler is installed. This issue is fixed in 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
{
"cwe_ids": [
"CWE-284"
],
"cna_assigner": "GitHub_M",
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/70xxx/CVE-2026-70612.json"
}{
"source": [
"AFFECTED_FIELD",
"REFERENCES"
],
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "39.8.8"
},
{
"introduced": "40.0.0-alpha.1"
},
{
"fixed": "40.9.0"
},
{
"introduced": "41.0.0-alpha.1"
},
{
"fixed": "41.2.1"
},
{
"introduced": "42.0.0-alpha.1"
},
{
"fixed": "42.0.0-beta.3"
}
]
}[
{
"digest": {
"length": 490.0,
"function_hash": "272553221120290705100734388975204268805"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3",
"signature_type": "Function",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc",
"function": "WebContents::SetHtmlApiFullscreen"
},
"signature_version": "v1",
"id": "CVE-2026-70612-12b8aaae"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"295245727707216907171073465136069292874",
"6437278666776489431995193783079558559",
"235319869943480694648745375954714737284",
"280487755501426453510632146498739767533",
"90274717499491430896947491967272155081",
"276891249822522492264138709938050342971",
"62355276529313650720466755089898991264",
"61261501448180252390559954374070078518",
"284423866056027312251031322392978894770",
"127517265636987617877620272510860098425",
"262637505527069304350490123020499441896",
"43745273640032134385846594203437245086",
"4518813979013008604276422589265742010",
"86164859897052592902837829788221460615",
"262031934296565717164015901377176348518",
"253524498316959475968433270548699050543",
"179833632638943298465004027569240384251",
"131745049384579512306325446681397454785",
"243749980607743046210510292717222071691"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a",
"signature_type": "Line",
"target": {
"file": "shell/browser/electron_browser_client.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70612-26210495"
},
{
"digest": {
"length": 571.0,
"function_hash": "221356461369192604599575695964876436598"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/2764e4c35168855f614876051823db4f58a3714a",
"signature_type": "Function",
"target": {
"file": "shell/browser/electron_browser_client.cc",
"function": "HandleExternalProtocolInUI"
},
"signature_version": "v1",
"id": "CVE-2026-70612-28e5eb51"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"15682146902651291502359085377717075897",
"276527650456380695295071685428336688423",
"74027944338977948308663562070351154643",
"239644526509655375329227422095204640925"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/8ee008ad48671e179d1b8258879871709babfff3",
"signature_type": "Line",
"target": {
"file": "shell/browser/api/electron_api_web_contents.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70612-60dfa0b4"
},
{
"digest": {
"length": 571.0,
"function_hash": "221356461369192604599575695964876436598"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/477dcf7afc6550715f9ec5e6f39ee38e5dd7bf39",
"signature_type": "Function",
"target": {
"file": "shell/browser/electron_browser_client.cc",
"function": "HandleExternalProtocolInUI"
},
"signature_version": "v1",
"id": "CVE-2026-70612-6e8bade1"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"324922543804784637680679815153599826403",
"6437278666776489431995193783079558559",
"235319869943480694648745375954714737284",
"280487755501426453510632146498739767533",
"90274717499491430896947491967272155081",
"276891249822522492264138709938050342971",
"62355276529313650720466755089898991264",
"61261501448180252390559954374070078518",
"284423866056027312251031322392978894770",
"127517265636987617877620272510860098425",
"262637505527069304350490123020499441896",
"43745273640032134385846594203437245086",
"4518813979013008604276422589265742010",
"86164859897052592902837829788221460615",
"262031934296565717164015901377176348518",
"253524498316959475968433270548699050543",
"179833632638943298465004027569240384251",
"131745049384579512306325446681397454785",
"243749980607743046210510292717222071691"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5",
"signature_type": "Line",
"target": {
"file": "shell/browser/electron_browser_client.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70612-7b93de7b"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"74011027212765586007018775702082750448",
"6437278666776489431995193783079558559",
"235319869943480694648745375954714737284",
"280487755501426453510632146498739767533",
"90274717499491430896947491967272155081",
"276891249822522492264138709938050342971",
"62355276529313650720466755089898991264",
"61261501448180252390559954374070078518",
"284423866056027312251031322392978894770",
"127517265636987617877620272510860098425",
"262637505527069304350490123020499441896",
"43745273640032134385846594203437245086",
"4518813979013008604276422589265742010",
"86164859897052592902837829788221460615",
"262031934296565717164015901377176348518",
"253524498316959475968433270548699050543",
"179833632638943298465004027569240384251",
"131745049384579512306325446681397454785",
"243749980607743046210510292717222071691"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/c39e3d5687d57434c8d5fe814c5152efd2f631c3",
"signature_type": "Line",
"target": {
"file": "shell/browser/electron_browser_client.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70612-b42d7029"
},
{
"digest": {
"length": 571.0,
"function_hash": "221356461369192604599575695964876436598"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/c39e3d5687d57434c8d5fe814c5152efd2f631c3",
"signature_type": "Function",
"target": {
"file": "shell/browser/electron_browser_client.cc",
"function": "HandleExternalProtocolInUI"
},
"signature_version": "v1",
"id": "CVE-2026-70612-d54e819e"
},
{
"digest": {
"length": 571.0,
"function_hash": "221356461369192604599575695964876436598"
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/08b9d0a220e267d1a2402a44bdd01a2e9aa320b5",
"signature_type": "Function",
"target": {
"file": "shell/browser/electron_browser_client.cc",
"function": "HandleExternalProtocolInUI"
},
"signature_version": "v1",
"id": "CVE-2026-70612-f08001af"
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"295245727707216907171073465136069292874",
"6437278666776489431995193783079558559",
"235319869943480694648745375954714737284",
"280487755501426453510632146498739767533",
"90274717499491430896947491967272155081",
"276891249822522492264138709938050342971",
"62355276529313650720466755089898991264",
"61261501448180252390559954374070078518",
"284423866056027312251031322392978894770",
"127517265636987617877620272510860098425",
"262637505527069304350490123020499441896",
"43745273640032134385846594203437245086",
"4518813979013008604276422589265742010",
"86164859897052592902837829788221460615",
"262031934296565717164015901377176348518",
"253524498316959475968433270548699050543",
"179833632638943298465004027569240384251",
"131745049384579512306325446681397454785",
"243749980607743046210510292717222071691"
]
},
"deprecated": false,
"source": "https://github.com/electron/electron/commit/477dcf7afc6550715f9ec5e6f39ee38e5dd7bf39",
"signature_type": "Line",
"target": {
"file": "shell/browser/electron_browser_client.cc"
},
"signature_version": "v1",
"id": "CVE-2026-70612-f7e1b993"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-70612.json"
"2026-08-07T22:16:26Z"