Executive brief
Google Chrome includes WebXR, a feature that enables immersive web experiences like virtual and augmented reality. An uninitialized variable in this component could allow attackers to leak sensitive data from other websites if a user is tricked into visiting a malicious webpage. This could expose personal information or credentials from other sites the user has open.
Technical details
An uninitialized resource vulnerability exists in the WebXR module of Google Chrome prior to version 152.0.7977.65. The vulnerability is triggered when WebXR fails to properly initialize a variable before use, leaving it containing arbitrary data from memory. An attacker can exploit this via a crafted HTML page that leverages social engineering to trick a user into visiting the malicious site. Successful exploitation allows cross-origin data leakage, potentially exposing sensitive information from other websites in the user's browser context. The vulnerability was patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65