Electron: Sandboxed iframes can launch external protocol handlers (CVE-2026-70612)
A vulnerability in Electron allows sandboxed iframes to launch external protocol handlers without respecting sandbox restrictions. This affects apps rendering untrusted content in sandboxed iframes that grant the openExternal permission by default. The issue is fixed in Electron versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
AI Analysis
Technical Summary
Electron versions prior to 39.8.8 do not properly enforce iframe sandbox restrictions when handling requests to open external protocol URLs. As a result, sandboxed iframes can trigger the launch of OS-registered external applications, bypassing sandbox protections. Additionally, the sandbox state of the iframe was not exposed to the app's permission handlers, preventing proper permission checks. This vulnerability affects applications that render untrusted content in sandboxed iframes and grant the openExternal permission, which is granted by default if no setPermissionRequestHandler is installed. The issue is addressed by denying openExternal permission for untrusted content or upgrading to fixed Electron versions.
Potential Impact
An attacker controlling content in a sandboxed iframe could cause the Electron app to launch external applications registered with the operating system. This could lead to unintended execution of external programs, potentially increasing the attack surface. However, apps that deny openExternal permission for untrusted content are not affected. The CVSS score is 5.4 (medium severity), indicating limited confidentiality and integrity impact without availability impact.
Mitigation Recommendations
Upgrade Electron to version 39.8.8 or later (including 40.9.0, 41.2.1, or 42.0.0-beta.3) where this issue is fixed. Alternatively, implement a setPermissionRequestHandler that explicitly denies the openExternal permission for untrusted content to prevent sandboxed iframes from launching external protocol handlers.
Electron: Sandboxed iframes can launch external protocol handlers (CVE-2026-70612)
Description
A vulnerability in Electron allows sandboxed iframes to launch external protocol handlers without respecting sandbox restrictions. This affects apps rendering untrusted content in sandboxed iframes that grant the openExternal permission by default. The issue is fixed in Electron versions 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3.
CVSS v3.1
Score 5.4medium
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Electron versions prior to 39.8.8 do not properly enforce iframe sandbox restrictions when handling requests to open external protocol URLs. As a result, sandboxed iframes can trigger the launch of OS-registered external applications, bypassing sandbox protections. Additionally, the sandbox state of the iframe was not exposed to the app's permission handlers, preventing proper permission checks. This vulnerability affects applications that render untrusted content in sandboxed iframes and grant the openExternal permission, which is granted by default if no setPermissionRequestHandler is installed. The issue is addressed by denying openExternal permission for untrusted content or upgrading to fixed Electron versions.
Potential Impact
An attacker controlling content in a sandboxed iframe could cause the Electron app to launch external applications registered with the operating system. This could lead to unintended execution of external programs, potentially increasing the attack surface. However, apps that deny openExternal permission for untrusted content are not affected. The CVSS score is 5.4 (medium severity), indicating limited confidentiality and integrity impact without availability impact.
Mitigation Recommendations
Upgrade Electron to version 39.8.8 or later (including 40.9.0, 41.2.1, or 42.0.0-beta.3) where this issue is fixed. Alternatively, implement a setPermissionRequestHandler that explicitly denies the openExternal permission for untrusted content to prevent sandboxed iframes from launching external protocol handlers.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-p2rr-rvmm-c5fp
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-70612"]
- Ecosystems
- ["npm"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
Threat ID: 6a738518bf8831d5394eec1b
Added to database: 08/05/2026, 18:46:48 UTC
Last enriched: 08/05/2026, 23:46:01 UTC
Last updated: 08/05/2026, 23:46:01 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.