SecurityError: Blocked a frame with origin "x" from accessing a cross-origin frame.
Script tried to read or modify an iframe (or window) from another origin.
Seen on:
JavaScript
Meaning
The same-origin policy blocks access to cross-origin frames’ DOM. Use postMessage for communication.
Common causes
- Accessing iframe.contentWindow.document from another origin
- Reading window.opener across origins
- Different subdomains/ports count as different origins
⚡ Quick fix
- Communicate with window.postMessage and verify event.origin
- Serve both pages from the same origin if you control them
Detailed fix by platform
JavaScript
iframe.contentWindow.postMessage({ type: 'resize' }, 'https://child.example.com');
How to diagnose
- Origins — Parent vs frame origin (scheme, host, port)?
- Recent change — Did it start after a deploy, upgrade, or configuration change? Compare with the last working version.
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026