Executive brief
Google Chrome's extended reality (XR) feature in versions prior to 152.0.7977.65 contains an information leak vulnerability. A remote attacker can craft a malicious HTML page to trick users into visiting it, potentially exposing sensitive information from the browser or system. This could allow attackers to steal personal data, credentials, or other confidential information from affected users.
Technical details
This vulnerability is an information disclosure flaw in the XR (extended reality) component of Google Chrome. The vulnerability allows remote attackers to read or extract sensitive information through a specially crafted HTML page. The attack vector is network-based and requires user interaction (visiting a malicious webpage). No authentication is required. An attacker can exploit this to exfiltrate data that should be protected by the browser's security boundaries. The vulnerability has been patched in Chrome 152.0.7977.65 for Windows and Mac (152.0.7977.64 for Linux).
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched