Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6205-1 | chromium security update |
Mon, 13 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apple
Apple macos Linux Linux linux Kernel Microsoft Microsoft windows |
|
| CPEs | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Apple
Apple macos Linux Linux linux Kernel Microsoft Microsoft windows |
Mon, 13 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-693 | |
| Metrics |
cvssV3_1
|
ssvc
|
Mon, 13 Apr 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-601 |
Fri, 10 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | IFrameSandbox Policy Bypass Through Crafted HTML | chromium-browser: Policy bypass in IFrameSandbox |
| Weaknesses | CWE-838 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 09 Apr 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | IFrameSandbox Policy Bypass Through Crafted HTML | |
| First Time appeared |
Google
Google chrome |
|
| Weaknesses | CWE-601 | |
| Vendors & Products |
Google
Google chrome |
Wed, 08 Apr 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Policy bypass in IFrameSandbox in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low) | |
| References |
|
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-04-13T18:17:09.155Z
Reserved: 2026-04-08T19:34:43.635Z
Link: CVE-2026-5903
Updated: 2026-04-13T18:13:34.759Z
Status : Analyzed
Published: 2026-04-08T22:16:30.197
Modified: 2026-04-13T21:14:01.307
Link: CVE-2026-5903
OpenCVE Enrichment
Updated: 2026-04-14T16:37:26Z
Debian DSA