Threats Tagged 'cve-2026-70608'
View all threats tagged with 'cve-2026-70608'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2026-70608'
Click on any threat for detailed analysis and mitigation recommendations
Electron: Sandboxed iframe can bypass the allow-popups restriction via the OpenURL navigation path (CVE-2026-70608)CVE-2026-70608 0 A vulnerability in Electron allows sandboxed iframes without the 'allow-popups' permission to open new windows or trigger setWindowOpenHandler without user interaction. This occurs because new-window navigations using the OpenURL path do not enforce the iframe sandbox popup restriction. Applications embedding untrusted content in sandboxed iframes and relying solely on the absence of 'allow-popups' to prevent window creation are affected. Versions prior to 39.8.10 are vulnerable. Fixed versions include 39.8.10, 41.10.3, and 42.0.1. Join the discussion | GCVE Database | 08/05/2026, 17:27:18 UTC Added: 08/05/2026, 18:46:50 UTC |
Showing 1 to 1 of 1 result