Impact
The vulnerability arises from insufficient policy enforcement in Chrome’s WebXR API on Android before version 150.0.7871.47, allowing a remote attacker to craft a malicious HTML page that causes the browser to leak data from cross‑origin contexts. The exposed information violates the same‑origin policy and represents a medium‑severity information‑exposure flaw classified as CWE‑693.
Affected Systems
Chrome Android builds earlier than version 150.0.7871.47 are vulnerable when a user visits a malicious page that exploits the weakened WebXR policy.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while an EPSS score of less than 1% signals a very low probability of exploitation for now. The vulnerability is not listed in CISA KEV, meaning there are no known active exploits. The likely attack vector is simply a user navigating to a crafted HTML page, with no need for elevated privileges; the exploit relies solely on the victim’s Chrome instance and the browser’s incorrect handling of WebXR policy.
OpenCVE Enrichment
Debian DLA
Debian DSA