Sandbox attribute does not support "allow-popups-to-escape-sandbox" flag

Issue #10464339 • Assigned to Travis L.


Jeremie M.
Jan 9, 2017
This issue is public.
Found in
  • Microsoft Edge
  • Internet Explorer
Reported by 3 people

    • All major browsers (including Chrome, Safari and Firefox) support this now, except Edge and IE. It would be great if this could be prioritized.

      Ad networks are using those flags to sandbox ads, in order to prevent malicious behaviors.

    • Looking at the related sandbox bugs, I see that they were all closed as wontfix with a “helpful” link to

      It should not be up to the users to vote which features from the HTML standard they’d like implemented in Edge. These flags are not "user features", they’re part of the HTML spec describing how pages should be rendered.

      And in contrast to the related bugs, this attribute is much older than the others, widely supported by all major browsers, and a security feature. Without this flag, clicking on any link within a sandboxed iframe is completely useless even if the new link opens in a new tab, as most pages nowadays absolutely require JS.

      Currently, the only solution for Edge is to not use the sandbox at all, which security-wise is much worse. (For IE there was the workaround of using security=restricted, which has it’s own set of problems and is not available in Edge anymore).

    • For the record, someone added the uservoice “idea” here:

      It’s still unclear to me if this is a bug on an existing feature (Sandboxing), or if it counts as a new feature. In any case, voting on uservoice may help.

