Description
Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw occurs in the WebXR implementation of Google Chrome prior to version 151.0.7922.72. An attacker can supply a specially crafted HTML page that causes the browser to read memory beyond the bounds of a buffer, potentially exposing confidential information and compromising data confidentiality. This type of vulnerability is identified as CWE‑125 and carries a medium severity rating on the CVSS score list.

Affected Systems

The affected systems are users of Google Chrome versions earlier than 151.0.7922.72. The vulnerability is present in all builds of Chrome that include the WebXR component before this version.

Risk and Exploitability

The CVSS score is 8.1, indicating a high risk. The EPSS score of less than 1% suggests that the likelihood of exploitation is presently low, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by hosting a malicious web page that includes WebXR content; a user visiting the page would trigger the out‑of‑bounds read. No additional prerequisites beyond the ability to get the user to open the crafted page are documented in the CVE record.

Generated by OpenCVE AI on August 3, 2026 at 11:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.72 or later, which contains the bounds‑checking fix for the WebXR read flaw.
  • If an update is unavailable, avoid loading untrusted WebXR content by restricting access to unknown sites or disallowing WebXR APIs via browser settings or extensions.
  • As an interim workaround, disable the WebXR feature using a browser command‑line flag or experimental flag if the browser provides such an option, thereby preventing the read from occurring.

Generated by OpenCVE AI on August 3, 2026 at 11:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Out of bounds read in WebXR
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Out of bounds read in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-125
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T18:33:21.711Z

Reserved: 2026-07-27T23:35:08.293Z

Link: CVE-2026-17869

cve-icon Vulnrichment

Updated: 2026-07-31T18:33:15.173Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:50.817

Modified: 2026-08-03T17:43:17.793

Link: CVE-2026-17869

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:43Z

Links: CVE-2026-17869 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:00:16Z

Weaknesses