Description
Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unintended cross‑origin data exposure
Action: Apply Update
AI Analysis

Impact

The flaw is an incorrect authorization in Chrome’s WebXR implementation (CWE-863) that allows a remote attacker to gain access to data from other origins. By delivering a crafted HTML page that social‑engages a user, the attacker can reveal information that should have been protected by cross‑origin policy. The vulnerability does not provide direct code execution but enables unauthorized data disclosure.

Affected Systems

All desktop installations of Google Chrome versions earlier than 152.0.7977.65 are affected. The issue applies across operating systems that host the stable channel of Chrome.

Risk and Exploitability

The CVSS score of 6.5 classifies the vulnerability as medium. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not flagged in the CISA KEV catalog. The likely attack path requires a user to visit a malicious HTML page that trick them into enabling the WebXR feature, suggesting that social engineering is the primary vector. Although no public exploit modules are currently documented, the combination of the medium severity, low EPSS, and required user interaction means that the overall risk to organizations is moderate but not negligible.

Generated by OpenCVE AI on August 27, 2026 at 02:07 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or newer
  • Deploy a Chrome Enterprise policy to disable the WebXR feature or restrict it to secure contexts
  • Conduct a user awareness campaign to explain risks of malicious WebXR pages and report suspicious prompts

Generated by OpenCVE AI on August 27, 2026 at 02:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Exposure via Incorrect Authorization in WebXR chromium-browser: Google Chrome WebXR: Information disclosure via incorrect authorization
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 26 Aug 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:45:00 +0000

Type Values Removed Values Added
Title Cross-Origin Data Exposure via Incorrect Authorization in WebXR

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-28T17:59:11.999Z

Reserved: 2026-08-25T06:12:43.355Z

Link: CVE-2026-79258

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:20.340

Modified: 2026-08-31T13:48:46.733

Link: CVE-2026-79258

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-08-25T20:10:42Z

Links: CVE-2026-79258 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T02:15:04Z

Weaknesses