Policy Bypass in IFrameSandbox in Google Chrome by Google
CVE-2026-5903

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-5903?

A vulnerability exists in the IFrameSandbox feature of Google Chrome that allows remote attackers to circumvent navigation restrictions. By convincing users to perform specific UI actions, an attacker can exploit this weakness through a specially crafted HTML page, leading to unauthorized access to sensitive content or functionality within the browser.

Affected Version(s)

Chrome 147.0.7727.55

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.