Impact
The vulnerability originates from insufficient enforcement of policy restrictions in the WebXR API in Google Chrome for Android versions prior to 150.0.7871.47. A remote attacker can craft a malicious HTML page that, when rendered by the browser, causes Chrome to leak data that resides in a different origin. The flaw directly violates Chrome’s same‑origin policy, resulting in a confidentiality breach of user data. It is classified under CWE‑693, which indicates insufficient protection against the unauthorized release of information.
Affected Systems
All Android installations of Google Chrome with a version number below 150.0.7871.47 are affected. The vulnerability is triggered when a user visits a crafted HTML page that exploits the weakened WebXR policy. Users of older Android builds or those who have not updated Chrome are at risk.
Risk and Exploitability
The CVSS score of 6.5 denotes medium severity, while an EPSS score of less than 1 % indicates a very low probability that this weakness will be exploited in the near term. The vulnerability is not cataloged in CISA’s KEV list, signaling that no active exploit campaigns are presently known. The likely attack vector is a simple visit to a malicious webpage; no elevated privileges or additional user interaction beyond browsing are required.
OpenCVE Enrichment
Debian DLA
Debian DSA