Junglewise Threat Intelligence

CVE-2026-17796: Google Chrome side-channel information leakage in WebXR

CVE-2026-17796 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's WebXR component, which enables virtual and augmented reality experiences in the browser, contains a security vulnerability. A remote attacker could use a specially crafted website to trick the browser into leaking sensitive information from its memory. This could potentially expose private data or help an attacker bypass other security protections.

Technical details

A side-channel information leakage vulnerability exists in the WebXR implementation of Google Chrome. The flaw is categorized under CWE-1300 (Improper Protection of Physical Side Channels). By enticing a user to visit a maliciously crafted HTML page, a remote attacker can exploit timing or other side-channel behaviors to read sensitive data from the browser's process memory. This vulnerability was addressed in Chrome version 151.0.7922.72. No user authentication is required for exploitation beyond visiting the malicious site.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats