A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. This affects the function window.open of the component BrowserWindow. The manipulation results in improper input validation.

This vulnerability is reported as CVE-2026-70607. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.