Policy Bypass in IFrameSandbox in Google Chrome by Google
CVE-2026-5903
Currently unrated
What is CVE-2026-5903?
A vulnerability exists in the IFrameSandbox feature of Google Chrome that allows remote attackers to circumvent navigation restrictions. By convincing users to perform specific UI actions, an attacker can exploit this weakness through a specially crafted HTML page, leading to unauthorized access to sensitive content or functionality within the browser.
Affected Version(s)
Chrome 147.0.7727.55