Executive brief
A security vulnerability has been identified in Google Chrome's WebXR component, which is used to support virtual and augmented reality experiences in the browser. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's Same Origin Policy, potentially allowing them to access sensitive data from other websites the user has open.
Technical details
A vulnerability exists in the WebXR implementation of Google Chrome due to insufficient policy enforcement. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a malicious HTML page. SOP is a critical security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. By bypassing this, an attacker could potentially read data across security boundaries. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed