Executive brief
Google Chrome's WebXR component, which handles virtual and augmented reality experiences in the browser, contained a flaw that allowed for user interface (UI) spoofing. A remote attacker could use a specially crafted website to trick users into believing they are interacting with a legitimate part of the browser or a trusted site. This could lead to users inadvertently providing sensitive information or performing unintended actions due to the deceptive interface.
Technical details
An inappropriate implementation in the WebXR component of Google Chrome prior to version 150.0.7871.47 allowed a remote attacker to perform UI spoofing. By enticing a user to visit a specially crafted HTML page, the attacker could manipulate or overlay the browser's user interface elements. This vulnerability is categorized by Chromium as 'Low' severity and typically involves bypassing visual security indicators or misrepresenting the origin of content within the WebXR environment. The issue is resolved in Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Stable Channel update published
- 2026-06-30: patched: Fixed in version 150.0.7871.47