CVE-2026-5903
Description
A policy bypass flaw was found in the IFrameSandbox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=483771899
Statement
Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Understanding the Weakness (CWE)
Integrity,Confidentiality,Availability
Technical Impact: Modify Application Data; Execute Unauthorized Code or Commands
An attacker could modify the structure of the message or data being sent to the downstream component, possibly injecting commands.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.