« Volver al listado

CVE-2026-102673

Estado: En análisisAlta (8.2)—

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target="_blank" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

iframe sandbox bypass sin restricciones heredadas permite acceso a cookies, almacenamiento y scripting de origen (CWE-346). Requiere interacción del usuario (target=_blank, middle-click, UI:R).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-102673",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-102673",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-09-30T19:34:09.694143Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "electron",
          "product": "electron",
          "versions": [
            {
              "status": "affected",
              "version": "< 41.10.4"
            },
            {
              "status": "affected",
              "version": ">= 42.0.0-alpha.1, < 42.5.2"
            },
            {
              "status": "affected",
              "version": ">= 43.0.0-alpha.1, < 43.0.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-09-29T17:17:07.487",
  "references": [
    {
      "url": "https://github.com/electron/electron/commit/7ea14d5f55ecb11a30447701ddca16b3feee0bba",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/commit/e26b2640e7795c42bfb111b76009cbb4327c9a69",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/commit/ebe1165ee2b05c203c26dd2244ef1c5b9b1c04da",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/pull/52133",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/releases/tag/v41.10.4",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/releases/tag/v42.5.2",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/releases/tag/v43.0.0",
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/electron/electron/security/advisories/GHSA-hq2x-r82h-9wj4",
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Undergoing Analysis",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        },
        {
          "lang": "en",
          "value": "CWE-693"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron's OpenURLFromTab navigation path, including links using target=\"_blank\" or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application's full origin, exposing that origin's cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0."
    }
  ],
  "lastModified": "2026-09-30T21:17:04.917",
  "sourceIdentifier": "security-advisories@github.com"
}