Definition What does 'iframe sandbox detected' mean?
It means a browser extension, security scanner, or media player has found that the iframe it is embedded in carries the HTML sandbox attribute. The attribute limits what the frame can do: run scripts, submit forms, open popups, navigate the top-level page. The detection itself is not an attack; it is confirmation that sandboxing is in place. Whether that is the desired behavior depends on whether the embed needs the blocked capabilities to function.
Definition Why do video players ask to remove sandbox attributes on the iframe tag?
Most video embeds (YouTube, Vimeo, Dailymotion) need allow-scripts to run their player at all, usually allow-same-origin so the player can reach its own storage, and often allow-popups for share and watch-later links. A bare sandbox with none of those tokens stops the player executing any JavaScript, so it fails silently or shows the 'sandbox detected' warning. Autoplay and fullscreen come from a different mechanism: they are delegated through the iframe's allow attribute, for example allow="autoplay; fullscreen; picture-in-picture", which is Permissions Policy rather than sandbox. The fix is to add exactly the tokens the player documents rather than dropping sandbox, because sandbox is also what stops a cross-origin player submitting forms, opening popups, or navigating your top-level page away.
Definition Is it safe to remove sandbox attributes from an iframe?
Removing it lifts the browser-imposed restrictions on that frame: the embedded document can then execute scripts, submit forms, open popups, use plugins, and navigate your top-level page away. It does not hand a cross-origin embed access to your cookies or your DOM, because the same-origin policy already blocks that whether or not sandbox is present. The case that genuinely matters is a same-origin frame carrying allow-scripts and allow-same-origin together, since the framed document can then reach into the parent page and remove its own sandbox attribute. Keep sandbox, add only the specific tokens the embed documents, and serve untrusted embeds from a separate cookieless origin where possible.
Definition Does the sandbox attribute replace a Content Security Policy?
No. The sandbox attribute restricts what one embedded iframe can do, while a Content Security Policy governs what the whole page may load and execute. They cover different scopes and work best together: sandbox contains an untrusted embed, and CSP restricts scripts, connections, and framing across the document.
Definition Why is allow-scripts plus allow-same-origin considered dangerous?
Together they let the framed document run scripts with access to its real origin. If that origin is the embedder's, the frame can read the same data and even rewrite its own markup to drop the sandbox attribute, effectively escaping the restrictions you intended to impose.