Description
Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient policy enforcement in Chrome’s WebXR API on Android before version 150.0.7871.47, allowing a remote attacker to craft a malicious HTML page that causes the browser to leak data from cross‑origin contexts. The exposed information violates the same‑origin policy and represents a medium‑severity information‑exposure flaw classified as CWE‑693.

Affected Systems

Chrome Android builds earlier than version 150.0.7871.47 are vulnerable when a user visits a malicious page that exploits the weakened WebXR policy.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity, while an EPSS score of less than 1% signals a very low probability of exploitation for now. The vulnerability is not listed in CISA KEV, meaning there are no known active exploits. The likely attack vector is simply a user navigating to a crafted HTML page, with no need for elevated privileges; the exploit relies solely on the victim’s Chrome instance and the browser’s incorrect handling of WebXR policy.

Generated by OpenCVE AI on July 16, 2026 at 12:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer on Android.
  • If an immediate upgrade is not possible, disable the WebXR API via chrome://flags by setting the 'Experimental WebXR Features' flag to 'Disabled', then restart Chrome to mitigate the data‑leak risk.
  • If disabling WebXR is not feasible, avoid visiting untrusted websites, consider using a different browser that enforces WebXR policy correctly, or apply network‑level controls to block suspicious content.

Generated by OpenCVE AI on July 16, 2026 at 12:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient WebXR Policy Enforcement Enables Remote Cross‑Origin Data Leak in Chrome Android

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Insufficient WebXR Policy Enforcement Enables Remote Cross‑Origin Data Leak in Chrome Android

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title WebXR Cross‑Origin Data Leakage in Google Chrome Android

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title WebXR Cross‑Origin Data Leakage in Google Chrome Android

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement in WebXR Enables Cross‑Origin Data Leak

Thu, 09 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement in WebXR Enables Cross‑Origin Data Leak

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via WebXR Policy Bypass in Android Chrome

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via WebXR Policy Bypass in Android Chrome

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title WebXR Policy Enforcement Weakness Allows Cross‑Origin Data Leak in Chrome for Android

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title WebXR Policy Enforcement Weakness Allows Cross‑Origin Data Leak in Chrome for Android

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via WebXR in Chrome on Android

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Cross‑Origin Data Leak via WebXR in Chrome on Android

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via WebXR Policy Bypass in Chrome for Android

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via WebXR Policy Bypass in Chrome for Android

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title WebXR API Policy Bypass Allowing Cross‑Origin Data Exfiltration in Chrome for Android

Thu, 02 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title WebXR API Policy Bypass Allowing Cross‑Origin Data Exfiltration in Chrome for Android

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title WebXR Cross‑Origin Data Leak in Android Chrome
Weaknesses CWE-200

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title WebXR Cross‑Origin Data Leak in Android Chrome
Weaknesses CWE-200

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via Insufficient WebXR Policy Enforcement in Chrome on Android
Weaknesses CWE-200
CWE-285

Wed, 01 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Leak via Insufficient WebXR Policy Enforcement in Chrome on Android
Weaknesses CWE-200
CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:13:24.167Z

Reserved: 2026-06-29T23:03:49.942Z

Link: CVE-2026-13910

cve-icon Vulnrichment

Updated: 2026-07-01T14:13:15.849Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure