Junglewise Threat Intelligence

CVE-2026-5903: Google Chrome policy bypass in IFrameSandbox

CVE-2026-5903 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a popular web browser used to access the internet and run web applications. A security flaw in the browser's sandbox mechanism could allow a malicious website to bypass navigation restrictions if a user performs specific interactions. This could lead to unauthorized navigation or the circumvention of security policies intended to isolate untrusted web content.

Technical details

A policy bypass vulnerability exists in the IFrameSandbox component of Google Chrome prior to version 147.0.7727.55. The flaw is categorized as a protection mechanism failure (CWE-693) where navigation restrictions can be bypassed. An attacker can exploit this by hosting a crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation allows the attacker to bypass sandbox-enforced navigation policies. The issue was addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-11: other: Reported to vendor
  • 2026-04-07: patched: Fixed in version 147.0.7727.55
  • 2026-04-08: disclosed: Initial NVD publication

References

Related threats