It’s proposed that by default the following permissions cannot be requested or granted to content contained in cross-origin iframes:
-Geolocation
-Midi
-Encrypted media extensions
-Microphone and Camera
In order for a cross-origin frame to get access to these permissions, the embedding page must specify a Feature Policy which enables the feature for the frame. For example, to enable geolocation in an iframe, the embedder could specify the iframe tag as:
<iframe src="https://example.com" allow="geolocation"></iframe>
Comment 1 by bugdroid1@chromium.org
, May 24 2017