CVE-2026-17823

Description

A flaw was found in Google Chrome's WebXR component. This vulnerability, caused by insufficient policy enforcement, could allow a remote attacker to bypass the same-origin policy. By crafting a malicious HTML page, an attacker could exploit this to gain unauthorized access to sensitive information or actions across different web origins.

Statement

This vulnerability in the WebXR component of chromium-browser is rated as Important. A remote attacker could exploit insufficient policy enforcement to bypass the same-origin policy through a crafted HTML page, potentially leading to unauthorized access to sensitive information. User interaction, such as visiting a malicious website, is required for exploitation.

Understanding the Weakness (CWE)

Access Control,Other

Technical Impact: Gain Privileges or Assume Identity; Varies by Context

An attacker can access any functionality that is inadvertently accessible to the source.

Frequently Asked Questions

Want to get errata notifications? Sign up here.