Sceawere

Vulnerability Detail

CVE-2026-79125UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Google Chrome XR Information Disclosure

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Information leak in XR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive information via a crafted HTML page. (Chromium security severity: Low)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-25T21:18:07.653Z",
  "pubdate": "2026-08-25T21:18:07.653Z",
  "executiveSummary": "This vulnerability is an information disclosure flaw identified within the XR (Extended Reality) component of the Google Chrome browser.\nThe vulnerability allows a remote, unauthenticated attacker to extract sensitive data from the user's environment through a specifically crafted HTML document.\nThe flaw affects all versions of Google Chrome prior to 152.0.7977.65.\nThe security impact is classified as Low severity by the Chromium project, reflecting that while data confidentiality is compromised, the exploit complexity and potential scope are constrained.\nSuccessful exploitation requires a user to navigate to a malicious webpage, where the browser's XR implementation fails to properly isolate or sanitize information during interaction.\nRisk implications include the potential for unauthorized access to device or environment data managed by the XR API, which could be leveraged to gain insights into the user's local context.\nBecause the vector is a remote attacker utilizing standard browser-based delivery, the attack does not require prior authentication or elevated privileges, relying instead on the victim's interaction with the malicious content.",
  "technicalDetails": "The root cause of this vulnerability lies in an improper implementation of security boundaries within the XR (Extended Reality) subsystem of the Chromium engine. XR modules in web browsers are designed to interface with hardware sensors, spatial mapping data, and peripheral input devices to facilitate immersive web experiences.\nThe vulnerability occurs because the XR component fails to sufficiently validate the origin or scope of requests originating from an untrusted HTML page, leading to a breakdown in the expected security isolation mechanisms intended to protect environment-specific sensitive information.\nExploitation is achieved through the delivery of a crafted HTML page containing malicious scripts designed to invoke specific XR API methods. When a user visits the page, the script executes within the context of the browser and triggers an insecure state in the XR module.\nThe attack flow follows these steps: 1) The attacker hosts a malicious document designed to interface with the XR API; 2) The victim browses to the malicious URL using an affected version of Google Chrome; 3) The browser's XR component processes the attacker's requests; 4) Due to the lack of adequate validation, the component leaks sensitive data—potentially related to device metadata, spatial positioning, or user context—back to the attacker's script; 5) The attacker captures this information and transmits it to an external server.\nThe vulnerable component is the Chromium XR implementation, which governs how web content interacts with immersive hardware and spatial APIs. Because the API surface of XR is extensive, if access controls are not strictly enforced during the handshake between the DOM and the XR runtime, information flows across trust boundaries.\nThis vulnerability is classified as remote, as it does not require local access or authentication; it is initiated by the victim's interaction with web content. The privilege level is the standard user level, meaning the exploit operates within the security sandbox of the browser process, yet utilizes the API-level flaw to bypass data leakage protections.\nThe post-exploitation impact involves the unauthorized exfiltration of information that the browser would otherwise consider private. While the scope is limited to the data accessible through the XR API, this could include configuration details or environmental insights that assist in fingerprinting or further targeted attacks."
}
CVE-2026-79125: Google Chrome XR Information Disclosure (MEDIUM Severity, CVSS: 6.5) - Sceawere