Impact
A flaw in the WebXR implementation of Google Chrome allows a remote attacker to serve a specially crafted HTML page that can spoof user interface elements, potentially misleading users into interacting with deceptive content that appears to be legitimate. The weakness stems from improper validation of WebXR rendering requests, which can be exploited to overlay or replace UI components on a victim’s screen.
Affected Systems
All installations of Google Chrome earlier than version 150.0.7871.47 are affected; no other browsers are reported to be vulnerable.
Risk and Exploitability
Chromium labels the bug as low severity, reflected in a CVSS score of 4.3 and an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog. Exploitation would typically occur when a user visits a malicious WebXR-enabled web page, and it requires no additional privileges or software on the victim’s machine.
OpenCVE Enrichment
Debian DLA
Debian DSA