Executive brief
A security issue in Google Chrome for Android could allow a malicious website to bypass standard navigation restrictions. This occurs within the WebXR component, which handles virtual and augmented reality experiences in the browser. An attacker could use a specially crafted webpage to force the browser to navigate in ways that are normally restricted, potentially leading to unauthorized site transitions or user confusion.
Technical details
A navigation restriction bypass exists in the WebXR implementation of Google Chrome for Android. The vulnerability is classified as an 'Inappropriate Implementation' within the WebXR component, which manages VR/AR content. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger unintended navigation actions that bypass security boundaries. This is rated as Low severity by Chromium. The issue is resolved in version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched