CVE-2026-5903

Description

A policy bypass flaw was found in the IFrameSandbox component of the Chromium browser.

Upstream bug(s):

https://code.google.com/p/chromium/issues/detail?id=483771899

Statement

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Understanding the Weakness (CWE)

Integrity,Confidentiality,Availability

Technical Impact: Modify Application Data; Execute Unauthorized Code or Commands

An attacker could modify the structure of the message or data being sent to the downstream component, possibly injecting commands.

Frequently Asked Questions

Want to get errata notifications? Sign up here.