Executive brief
Google Chrome's WebXR component, which handles virtual and augmented reality content, contained a flaw that could allow a malicious website to access sensitive information. By tricking a user into visiting a specially crafted webpage, an attacker could potentially read data from the browser's memory. This could lead to the exposure of private information from other open tabs or browser processes.
Technical details
An information disclosure vulnerability exists in the WebXR implementation of Google Chrome. The flaw is characterized as an 'inappropriate implementation' that fails to properly isolate or protect process memory when processing WebXR content. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to read sensitive data from the browser's process memory. This issue was addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: advisory: Chrome Stable Channel Update published
- 2026-07-30: disclosed: NVD publication date