CVE-2026-34765 Details
Description
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a target name, Electron did not correctly scope the named-window lookup to the opener's browsing context group. A renderer could navigate an existing child window that was opened by a different, unrelated renderer if both used the same target name. If that existing child was created with more permissive webPreferences (via setWindowOpenHandler's overrideBrowserWindowOptions), content loaded by the second renderer inherits those permissions. Apps are only affected if they open multiple top-level windows with differing trust levels and use setWindowOpenHandler to grant child windows elevated webPreferences such as a privileged preload script. Apps that do not elevate child window privileges, or that use a single top-level window, are not affected. Apps that additionally grant nodeIntegration: true or sandbox: false to child windows (contrary to the security recommendations) may be exposed to arbitrary code execution. This vulnerability is fixed in 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5.
A vulnerability exists in Electron prior to versions 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, where the window.open() function did not properly restrict named-window lookups to the opener's browsing context group. This flaw allows a renderer to manipulate an existing child window opened by a different renderer, provided both use the same target name. If the child window had more lenient webPreferences (through setWindowOpenHandler's overrideBrowserWindowOptions), the second renderer could exploit this by inheriting those permissions. This issue affects applications that open multiple top-level windows with varying trust levels and use setWindowOpenHandler to assign elevated webPreferences to child windows, such as a privileged preload script. Applications that maintain a single top-level window or do not elevate child window privileges are not impacted. Furthermore, apps that grant nodeIntegration: true or sandbox: false to child windows, against security best practices, could face arbitrary code execution risks.
To address this vulnerability, update Electron to version 39.8.5, 40.8.5, 41.1.0, or 42.0.0-alpha.5. For applications that cannot be updated, consider denying window.open() in renderers that load untrusted content by returning { action: 'deny' } from setWindowOpenHandler. Avoid granting child windows more permissive webPreferences than their opener.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/electron/electron/security/advisories/GHSA-f3pv-wv63-48x8 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-668 | Exposure of Resource to Wrong Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| electronjs electron | <= 39.8.4 >= 40.0.0, <= 40.8.4 >= 41.0.0, < 41.1.0 41.2.0 42.0.0 alpha1 42.0.0 alpha2 42.0.0 alpha3 42.0.0 alpha4 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | Initial Analysis | [email protected] |
| Apr 7, 2026 | New CVE Received | [email protected] |