CVE-2026-70612: Iframe Sandbox Escape and Host Protocol Launch in Electron
Vulnerability ID: CVE-2026-70612
CVSS Score: 5.4
Published: 2026-08-05
Improper access control in Electron versions prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3 allowed sandboxed iframes to bypass sandbox restrictions and trigger external application protocols on the host operating system. The application's custom permission handler was also not provided with the frame's sandbox state, preventing effective validation of the request context.
TL;DR
A validation flaw in Electron allowed sandboxed iframes to bypass security restrictions and launch OS-registered external protocol handlers without authorization.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-284 (Improper Access Control)
- Attack Vector: Network
- CVSS v3.1 Score: 5.4
- EPSS Score: Not indexed
- Impact: Medium (Scope Change, potential host-level command execution)
- Exploit Status: Proof of Concept (PoC) available
- KEV Status: Not listed in CISA KEV
Affected Systems
- Electron applications rendering untrusted content in sandboxed iframes without rigorous custom permission handlers.
-
electron: < 39.8.8 (Fixed in:
39.8.8) -
electron: >= 40.0.0-alpha.1 < 40.9.0 (Fixed in:
40.9.0) -
electron: >= 41.0.0-alpha.1 < 41.2.1 (Fixed in:
41.2.1) -
electron: >= 42.0.0-alpha.1 < 42.0.0-beta.3 (Fixed in:
42.0.0-beta.3)
Code Analysis
Commit: 08b9d0a
Fix: block external protocol navigation in sandboxed iframes (branch 39)
Commit: 2764e4c
Fix: block external protocol navigation in sandboxed iframes (branch 40)
Commit: 477dcf7
Fix: block external protocol navigation in sandboxed iframes (branch 41)
Commit: c39e3d5
Fix: block external protocol navigation in sandboxed iframes (branch 42)
Exploit Details
- GitHub: Official advisory with details of sandbox bypassing functionality and references to testing specifications.
Mitigation Strategies
- Upgrade the Electron framework to patched versions to ensure proper validation of iframe sandbox flags.
- Configure setPermissionRequestHandler to manually inspect and filter openExternal permission requests.
- Implement strong Content Security Policies (CSP) to restrict allowed navigation endpoints.
Remediation Steps:
- Identify the current Electron version used in package.json.
- Update package.json dependencies to set electron >= 39.8.8, >= 40.9.0, >= 41.2.1, or >= 42.0.0-beta.3.
- Install dependencies and rebuild the application binary.
- Review custom setPermissionRequestHandler configurations and enforce strict origin-based blacklists for openExternal actions.
References
- Electron Security Advisory (GHSA-p2rr-rvmm-c5fp)
- Chromium Status: Restriction of navigation to custom protocols from sandboxed iframes
Read the full report for CVE-2026-70612 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)