Junglewise Threat Intelligence

CVE-2026-17823: Google Chrome Same Origin Policy bypass in WebXR

CVE-2026-17823 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's WebXR component, which is used to support virtual and augmented reality experiences in the browser. A remote attacker could exploit this flaw by tricking a user into visiting a specially crafted website. If successful, the attacker could bypass the browser's Same Origin Policy, potentially allowing them to access sensitive data from other websites the user has open.

Technical details

A vulnerability exists in the WebXR implementation of Google Chrome due to insufficient policy enforcement. The flaw allows a remote attacker to bypass the Same Origin Policy (SOP) by enticing a user to visit a malicious HTML page. SOP is a critical security mechanism that restricts how a document or script loaded from one origin can interact with a resource from another origin. By bypassing this, an attacker could potentially read data across security boundaries. The issue is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched
  • 2026-07-30: disclosed

References

Related threats