PT-2026-31521 · Google · Google Chrome

Ciarands

·

Published

2026-02-11

·

Updated

2026-04-12

·

CVE-2026-5903

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.55
Description A security flaw exists within the iFrameSandbox component of the Google Chrome browser, impacting data protection mechanisms. Successful exploitation could allow a remote attacker to circumvent security restrictions. Specifically, a policy bypass in IFrameSandbox prior to version 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions through a specially crafted HTML page, requiring specific user interaction.
Recommendations Update Google Chrome to version 147.0.7727.55 or later.

Fix

Protection Mechanism Failure

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-04938
CVE-2026-5903
OPENSUSE-SU-2026:10530-1
OPENSUSE-SU-2026:20575-1

Affected Products

Google Chrome