Impact
The flaw occurs in the WebXR implementation of Google Chrome prior to version 151.0.7922.72. An attacker can supply a specially crafted HTML page that causes the browser to read memory beyond the bounds of a buffer, potentially exposing confidential information and compromising data confidentiality. This type of vulnerability is identified as CWE‑125 and carries a medium severity rating on the CVSS score list.
Affected Systems
The affected systems are users of Google Chrome versions earlier than 151.0.7922.72. The vulnerability is present in all builds of Chrome that include the WebXR component before this version.
Risk and Exploitability
The CVSS score is 8.1, indicating a high risk. The EPSS score of less than 1% suggests that the likelihood of exploitation is presently low, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by hosting a malicious web page that includes WebXR content; a user visiting the page would trigger the out‑of‑bounds read. No additional prerequisites beyond the ability to get the user to open the crafted page are documented in the CVE record.
OpenCVE Enrichment
Debian DLA
Debian DSA