Impact
An uninitialized resource in the WebXR subsystem of Google Chrome allowed a remote attacker to use a crafted HTML page to potentially access and leak cross‑origin data. The weakness results in information disclosure and does not grant arbitrary code execution or privilege escalation. The vulnerability was assigned medium severity by Chromium based on the data disclosure risk it poses.
Affected Systems
Google Chrome versions prior to 152.0.7977.65 are vulnerable. Any installation that uses the WebXR API in those builds is potentially affected; newer releases are not impacted.
Risk and Exploitability
The exploit requires social engineering to get a user to load a malicious page and depends on the presence of the WebXR API. No publicly available exploitation code is documented, and the EPSS score is < 1%. The CVSS score is 4.3, indicating medium severity. The vulnerability is not listed in CISA KEV. The risk is moderate to high for users who enable WebXR and are targeted by phishing or social engineering campaigns.
OpenCVE Enrichment
Debian DLA
Debian DSA