77ca6a6d12
setWindowOpenHandler opened details.url as a side effect before denying. Per GHSA-9f4c-93c8-jc8g (CVE-2026-70608, High 7.2), a sandboxed iframe with no allow-popups and no user gesture can reach this handler via the OpenURL path -- and the desktop renders untrusted artifact HTML in <iframe sandbox="allow-scripts">. A malicious artifact could therefore force the OS browser to an attacker URL with zero interaction. Electron ships no fixed 40.x release (fix is 41.10.3+/42.0.1), so we close it at the seam, version-independently. - electron/window-open-policy.ts: pure decideWindowOpen (always deny) + createWindowOpenHandler(onDenied) that denies and never opens a URL; the hook is logging-only. - main.ts: wireCommonWindowHandlers uses it (covers primary + all secondary/quick windows); the deny is logged, no side-effect open. - Trusted external links are unaffected: they already route through the audited hermes:openExternal IPC channel (openExternalUrl, http/https/ mailto allowlist). Converted the one remaining bare window.open on the Electron path (env-var docs menu) to openExternalLink; other window.open sites are bridge-absent web fallbacks. - tests-js/window-open-policy.test.ts: 4 tests pinning always-deny, the logging-only hook, and that a throwing hook never degrades to allow.