Executive brief
Google Chrome's WebXR feature (which enables immersive web experiences like virtual and augmented reality) contained an authorization flaw that allowed attackers to access cross-origin data through a crafted webpage. By using social engineering to trick users into visiting a malicious page, attackers could retrieve sensitive information from other websites the user had visited or was authenticated to.
Technical details
The vulnerability is an incorrect authorization flaw in Chrome's WebXR implementation (the standard API for extended reality features). The issue allows an attacker to access cross-origin data through a crafted HTML page without proper authorization checks. The attack requires user interaction (social engineering to visit a malicious page) but operates over the network once the page is loaded. A successful exploit could result in exposure of cross-origin data from other websites. The vulnerability was patched in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed: Disclosed in Chrome 152 release notes
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65