
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5903 is a policy bypass vulnerability in the IFrameSandbox component of Google Chrome that allows a remote attacker to circumvent navigation restrictions via a crafted HTML page. The vulnerability affects Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based). It was reported by researcher @Ciarands on February 11, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium), with Chromium internally classifying it as Low severity (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-693 (Protection Mechanism Failure), where Chrome's IFrameSandbox fails to correctly enforce navigation policy restrictions under certain conditions. An attacker can exploit this by hosting a crafted HTML page that, when visited by a victim who performs specific UI gestures (e.g., clicks or other interactions), causes the browser to bypass the sandbox's navigation restrictions. The attack requires no privileges and is network-delivered, but does require user interaction to trigger the policy bypass. The Chromium issue tracker references bug ID 483771899, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation primarily affects integrity, with a CVSS integrity impact rated High and no direct confidentiality or availability impact. An attacker could bypass IFrameSandbox navigation restrictions, potentially redirecting users to unintended or malicious destinations, circumventing same-origin policy protections enforced by the sandbox, or exposing users to content they would not otherwise encounter. While the vulnerability does not directly enable code execution or data theft, it could serve as a stepping stone in a multi-stage attack chain involving social engineering or malicious redirects (GitHub Advisory, Chrome Releases).
<iframe> element with specific attributes designed to trigger the IFrameSandbox policy bypass when the user interacts with the page.Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac). Microsoft has also released a corresponding update for Edge (Chromium-based). Users and administrators should update Chrome to version 147.0.7727.55 or later immediately via the browser's built-in update mechanism or enterprise deployment tools. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that included two Critical-severity CVEs (CVE-2026-5858 and CVE-2026-5859 in WebML), which drew more significant attention from the security community. Coverage of CVE-2026-5903 specifically was limited given its Low Chromium severity rating, though it was noted in broader roundups of the Chrome 147 patch batch by outlets such as GBHackers and BeyondMachines (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."