Junglewise Threat Intelligence

CVE-2026-17892: Google Chrome information disclosure in WebXR

CVE-2026-17892 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its WebXR component, which handles virtual and augmented reality content, could allow a malicious website to access sensitive information from the browser's memory. This could potentially lead to the exposure of private data from other open tabs or browser processes.

Technical details

A vulnerability classified as an inappropriate implementation exists in the WebXR component of Google Chrome. The flaw allows a remote attacker to perform an information disclosure attack by enticing a user to visit a specially crafted HTML page. By exploiting this issue, the attacker can read sensitive data from the browser's process memory. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Chromium developers have assigned this a security severity of Medium.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats