Executive brief
A security issue in Google Chrome's web page isolation feature could allow a malicious website to bypass intended navigation restrictions. This occurs when a website uses a 'sandbox' to limit what an embedded frame can do, but the browser fails to strictly enforce those rules. An attacker could use this to redirect users or navigate to unauthorized pages, potentially leading to phishing or other deceptive activities.
Technical details
A vulnerability exists in Google Chrome's IFrame Sandbox implementation due to insufficient policy enforcement. A remote attacker can exploit this by hosting a specially crafted HTML page that, when visited by a user, bypasses intended navigation restrictions within a sandboxed iframe. This allows the iframe to navigate to locations that should be restricted by the sandbox attributes. The issue was addressed in Chrome version 148.0.7778.168 for Windows.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2022-10-04: disclosed: Reported by Luan Herrera
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date