← WebKit Silent-Fix Report — 2026-W21

cbe41ae484  [Site Isolation] Fix http/tests/security/XFrameOptions/x-frame-options-ancestors-same-origin-deny.html

severity low class CrossOrigin confidence 0.50 WebCore bindings/Site Isolation
Anthony Tarbinian Tue May 19 11:28:30 2026 -0700 full: cbe41ae4841f2bb4621cf826de137e51664e3f02 bug report ↗ view on GitHub ↗
Primitive: cross-origin frame access error message leaked target origin
Triage note: Reduces a cross-origin info leak in the frame-access error message (though partly a refactor).

Security-relevant, below the exploitable-grade bar for a full root-cause writeup. The triage verdict is above; the side-by-side patch is below.

Before / after

Loading diff…