Impact
The flaw is an incorrect authorization in Chrome’s WebXR implementation (CWE-863) that allows a remote attacker to gain access to data from other origins. By delivering a crafted HTML page that social‑engages a user, the attacker can reveal information that should have been protected by cross‑origin policy. The vulnerability does not provide direct code execution but enables unauthorized data disclosure.
Affected Systems
All desktop installations of Google Chrome versions earlier than 152.0.7977.65 are affected. The issue applies across operating systems that host the stable channel of Chrome.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not flagged in the CISA KEV catalog. The likely attack path requires a user to visit a malicious HTML page that trick them into enabling the WebXR feature, suggesting that social engineering is the primary vector. Although no public exploit modules are currently documented, the combination of the medium severity, low EPSS, and required user interaction means that the overall risk to organizations is moderate but not negligible.
OpenCVE Enrichment
Debian DLA
Debian DSA