CVE detail
CVE-2026-70608
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user interaction because new-window navigations taking the OpenURL path did not apply the iframe sandbox popup restriction. Apps that embed untrusted content in sandboxed iframes and rely on the absence of allow-popups to prevent window creation are affected, while apps that deny window creation in setWindowOpenHandler or do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in 39.8.10, 41.10.3, and 42.0.1.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 5.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 10
- within the 30d window
- Peak daily
- 10
- highest bucket
Evidence
Source links by recency
10 source links · newest first
No excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PMNo excerpt available.
Exploitgithub.comAug 5, 2026, 6:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-59849CVSS 4.7 · Medium
Improper management of Content Security Policy in HCL BigFix Remote Control Lite Web Portal (versions 10.1.0.0326 and lower) may allow the execution of malicious code in web pages.
- CVE-2019-13924CVSS 5.4 · Medium
A vulnerability has been identified in SCALANCE S602 (All versions < V4.1), SCALANCE S612 (All versions < V4.1), SCALANCE S623 (All versions < V4.1), SCALANCE S627-2M (All version…
- CVE-2019-1975CVSS 6.1 · Medium
A vulnerability in the web-based interface of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to execute a cross-frame scripting (XFS) attack on an affect…
- CVE-2018-15423CVSS 4.7 · Medium
A vulnerability in the web UI of Cisco HyperFlex Software could allow an unauthenticated, remote attacker to affect the integrity of a device via a clickjacking attack. The vulner…
- CVE-2026-0293CVSS 5.6 · Medium
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unautho…
- CVE-2026-73288CVSS 6.1 · Medium
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_lock/objectlock_sys.rs lets ch…