Impact
Google Chrome’s WebXR feature contains an input validation flaw that allows a remote attacker to craft a web page that bypasses navigation restrictions. The vulnerability arises from insufficient sanitization of untrusted input passed to the WebXR subsystem, enabling the browser to ignore intended navigation constraints. A user who opens a malicious page can be redirected to arbitrary URLs, exposing them to potentially malicious sites.
Affected Systems
All desktop installations of Google Chrome earlier than version 150.0.7871.47 are affected. The flaw exists until that version is reached; newer releases no longer contain the vulnerability.
Risk and Exploitability
The issue is classified as low severity, with a CVSS score of 4.3. The EPSS score is less than 1 %, and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of widespread exploitation. Based on the description, exploitation requires a malicious web page that the user visits, making the attack vector remote via crafted content. No public exploits have been documented, and widespread attacks are considered unlikely, though the impact remains a navigation unwanted sites.
OpenCVE Enrichment
Debian DLA
Debian DSA