Impact
Google Chrome’s WebXR feature contains an input validation flaw that allows a remote attacker to craft a web page that bypasses navigation restrictions. The vulnerability arises when untrusted input is accepted by the WebXR subsystem, allowing a malicious page to redirect users to arbitrary URLs, potentially exposing them to malicious sites. The affected weakness permits a remote attacker to subvert the browser’s navigation restrictions, but it does not grant code execution or privilege escalation.
Affected Systems
All desktop installations of Google Chrome prior to version 150.0.7871.47 are affected. The flaw exists until that version is reached; newer releases no longer contain the vulnerability.
Risk and Exploitability
The issue is classified as low severity with a CVSS score of 4.3, and the EPSS score is less than 1 %, indicating a low probability of widespread exploitation. It is not listed in CISA’s KEV catalog. Based on the description, exploitation requires a malicious web page that the user visits, making the attack vector remote via crafted content. No public exploits have been documented, and widespread attacks are considered unlikely, though the impact remains that users may be directed to unintended sites.
OpenCVE Enrichment
Debian DLA
Debian DSA