Executive brief
Google Chrome is a widely used web browser. A vulnerability in its WebXR component, which handles virtual and augmented reality content, could allow a malicious website to read sensitive information from the computer's memory. This could potentially lead to the exposure of private data if a user visits a specially crafted web page.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in the WebXR component of Google Chrome prior to version 151.0.7922.72. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to perform an unauthorized memory read. This could lead to the disclosure of sensitive information from the browser's process memory. The attack requires no special privileges but does require user interaction (visiting a malicious site). Google has addressed this issue in the stable channel update 151.0.7922.72 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date