Executive brief
A vulnerability in Google Chrome's XR (Extended Reality) component could allow a malicious website to access sensitive information from the browser's memory. This occurs if an attacker first compromises the browser's rendering process and then lures a user to a specially crafted webpage. Successful exploitation could lead to the exposure of private data belonging to the user or other open browser tabs.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the XR component of Google Chrome. The flaw allows a remote attacker to read sensitive information from the process memory. To exploit this, an attacker must first achieve code execution within a compromised renderer process and then entice a user to visit a malicious HTML page. This memory leak can be used to bypass security mitigations or harvest sensitive data. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47