The X-Frame-Options HTTP header field protects pages against clickjacking attacks by allowing sites to opt-out of being embedded in cross-origin (or any) contexts.


Established standard

Status in Chromium


Enabled by default in:

  • Chrome for desktop release 4
  • Chrome for Android release 4
  • Chrome for iOS release 4
  • Android WebView release 4

Consensus & Standardization

After a feature ships in Chrome, the values listed here are not guaranteed to be up to date.

  • Shipped/Shipping
  • Shipped/Shipping
  • Shipped/Shipping
  • Positive


Last updated on 2020-11-09