Impact
A flaw in the WebXR implementation of Google Chrome on Android allows a remote attacker to loadvents the browser’s navigation restrictions. The weakness is classified as an authentication flaw (CWE‑284) and can result in unintended redirects to URLs chosen by the attacker. This does not establish a pathway for arbitrary code execution or privilege escalation according to the data provided.
Affected Systems
All Android devices running Google Chrome versions earlier than 150.0.7871.47 are potentially vulnerable. The update that fixes the issue was released in the June 2026 stable channel update for Chrome on Android.
Risk and Exploitability
The CVSS score is 4.3, indicating low severity, and the EPSS score is under 1 %, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can remotely trigger the bypass by hosting a crafted page that a user visits, potentially enabling phishing or social engineering through unintended navigation.
OpenCVE Enrichment
Debian DLA
Debian DSA