PT-2026-31521 · Google · Google Chrome
Ciarands
·
Published
2026-02-11
·
Updated
2026-04-12
·
CVE-2026-5903
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 147.0.7727.55
Description
A security flaw exists within the iFrameSandbox component of the Google Chrome browser, impacting data protection mechanisms. Successful exploitation could allow a remote attacker to circumvent security restrictions. Specifically, a policy bypass in IFrameSandbox prior to version 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions through a specially crafted HTML page, requiring specific user interaction.
Recommendations
Update Google Chrome to version 147.0.7727.55 or later.
Fix
Protection Mechanism Failure
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Google Chrome