Windows opened from a sandboxed top-level document did not inherit that document's HTML sandbox restrictions, so content that was meant to run sandboxed could open a window with the app's full origin. GHSA-hq2x-r82h-9wj4 covers the same issue for sandboxed iframes.
Apps are only affected if they render untrusted content in a sandboxed top-level document that allows popups. Apps that deny popups from untrusted content with setWindowOpenHandler are not affected.
Return { action: 'deny' } from setWindowOpenHandler for windows opened by untrusted content.
44.0.0-beta.543.4.142.9.241.10.6If you have any questions or comments about this advisory, email us at security@electronjs.org
{
"cwe_ids": [
"CWE-266",
"CWE-693"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T18:05:11Z",
"nvd_published_at": null,
"severity": "HIGH"
}