CSP with ACAO

Violate iframe with example.com

<iframe src="https://example.com"></iframe>