天下漏洞,尽知其名
HIGH

CVE-2026-102673 Electron 沙箱 iframe 弹窗绕过漏洞

影响攻击者可绕过沙箱限制访问应用源下的 Cookie 与存储

AI 研判

Electron 是使用 JavaScript、HTML 和 CSS 编写跨平台桌面应用的框架。在 41.10.4、42.5.2、43.0.0 之前版本中,从沙箱化 iframe 经 OpenURLFromTab 导航路径打开的弹窗未继承 HTML 沙箱限制。使用 allow-scripts allow-popups 配置的不可信 iframe 可打开具有嵌入应用完整源的弹窗,从而暴露该源的 Cookie、存储及同源脚本能力。

影响范围

Electron

Electron 41.10.4、42.5.2、43.0.0 之前的版本受影响;未在沙箱 iframe 中嵌入不可信内容的应用不受影响。

漏洞详情

漏洞类型为沙箱绕过/同源策略失效。成因是 Electron 的 OpenURLFromTab 导航路径在打开弹窗时未将父级 iframe 的 HTML sandbox 属性传递给新窗口。攻击者可在 allow-scripts allow-popups 的不可信 iframe 中通过 target="_blank" 或中键点击打开弹窗,使其获得嵌入应用的完整源,进而读取 Cookie、本地存储并执行同源脚本。

利用条件与风险

利用前提是应用在沙箱化 iframe 中嵌入了不可信内容并允许脚本与弹窗。实战中可能导致会话劫持、敏感数据窃取等风险,CVSS 8.2 属高危。

修复建议

升级至 Electron 41.10.4、42.5.2 或 43.0.0 及以上版本。临时缓解措施为不在沙箱 iframe 中嵌入不可信内容,或移除 allow-popups 等宽松沙箱配置。

原始情报

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 41.10.4, 42.5.2, and 43.0.0, popups opened from a sandboxed iframe through Electron’s OpenURLFromTab navigation path, including links using target=”_blank” or a middle-click, did not receive the inherited HTML sandbox restrictions. An untrusted iframe using the allow-scripts allow-popups configuration could therefore open a popup with the embedding application’s full origin, exposing that origin’s cookies, storage, and same-origin scripting capabilities. Applications that do not embed untrusted content in sandboxed iframes are not affected. This issue is fixed in versions 41.10.4, 42.5.2, and 43.0.0.