Description
Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Potential cross‑origin data leakage
Action: Apply Update
AI Analysis

Impact

An uninitialized resource in the WebXR subsystem of Google Chrome allowed a remote attacker to use a crafted HTML page to potentially access and leak cross‑origin data. The weakness results in information disclosure and does not grant arbitrary code execution or privilege escalation. The vulnerability was assigned medium severity by Chromium based on the data disclosure risk it poses.

Affected Systems

Google Chrome versions prior to 152.0.7977.65 are vulnerable. Any installation that uses the WebXR API in those builds is potentially affected; newer releases are not impacted.

Risk and Exploitability

The exploit requires social engineering to get a user to load a malicious page and depends on the presence of the WebXR API. No publicly available exploitation code is documented, and the EPSS score is < 1%. The CVSS score is 4.3, indicating medium severity. The vulnerability is not listed in CISA KEV. The risk is moderate to high for users who enable WebXR and are targeted by phishing or social engineering campaigns.

Generated by OpenCVE AI on August 26, 2026 at 22:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Chrome 152.0.7977.65 or later.
  • If an update cannot be applied immediately, configure Chrome to disable the WebXR API through browser policy or flags.
  • Implement user training to recognize phishing and social engineering attempts that may attempt to exploit WebXR.

Generated by OpenCVE AI on August 26, 2026 at 22:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:30:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource in Chrome WebXR Enables Potential Cross‑Origin Data Leak

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Uninitialized Resource in Chrome WebXR Enables Potential Cross‑Origin Data Leak

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-908
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T19:53:05.441Z

Reserved: 2026-08-25T06:05:14.902Z

Link: CVE-2026-78962

cve-icon Vulnrichment

Updated: 2026-08-26T19:49:50.332Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:52.287

Modified: 2026-08-27T17:33:30.930

Link: CVE-2026-78962

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T22:15:05Z

Weaknesses
  • CWE-908

    Use of Uninitialized Resource