Junglewise Threat Intelligence

CVE-2026-17889: Google Chrome uninitialized use in WebXR

CVE-2026-17889 · Severity: info · CVSS 4.3 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's WebXR component, which is used to handle virtual and augmented reality content in the browser. A remote attacker could use a specially crafted website to access sensitive information from other websites the user has open. This could lead to the unauthorized disclosure of private user data or browsing activity.

Technical details

An uninitialized variable vulnerability (CWE-457) exists in the WebXR component of Google Chrome. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to bypass cross-origin isolation. By exploiting this uninitialized state, an attacker can read memory contents that may contain sensitive data from different origins. The vulnerability is reachable over the network and requires user interaction (visiting a malicious site). Google has addressed this issue in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released a stable channel update addressing the issue.
  • 2026-07-30: disclosed: CVE published in the NVD.

References

Related threats