Junglewise Threat Intelligence

CVE-2026-14073: Google Chrome navigation restriction bypass in WebXR

CVE-2026-14073 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability was identified in Google Chrome's WebXR component, which is used to support virtual and augmented reality experiences in the browser. A remote attacker could use a specially crafted website to bypass security restrictions that normally control how the browser navigates between pages. While rated as low severity, this could potentially be used to mislead users or facilitate further attacks by circumventing intended navigation boundaries.

Technical details

A vulnerability exists in the WebXR component of Google Chrome due to insufficient validation of untrusted input. By enticing a user to visit a specially crafted HTML page, a remote attacker can exploit this flaw to bypass navigation restrictions. This class of vulnerability typically involves the failure to properly sanitize or verify parameters used during page transitions or frame management within the XR environment. The issue is addressed in Google Chrome version 150.0.7871.47 and later. The Chromium project has assigned this a 'Low' severity rating.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats