← WebKit Silent-Fix Report — 2026-W21
cbe41ae484 [Site Isolation] Fix http/tests/security/XFrameOptions/x-frame-options-ancestors-same-origin-deny.html
severity low
class CrossOrigin
confidence 0.50
WebCore bindings/Site Isolation
Primitive: cross-origin frame access error message leaked target origin
Triage note: Reduces a cross-origin info leak in the frame-access error message (though partly a refactor).
Triage note: Reduces a cross-origin info leak in the frame-access error message (though partly a refactor).
Security-relevant, below the exploitable-grade bar for a full root-cause writeup. The triage verdict is above; the side-by-side patch is below.
Before / after
Loading diff…