Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-17823

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

A flaw was found in Google Chrome's WebXR component. This vulnerability, caused by insufficient policy enforcement, could allow a remote attacker to bypass the same-origin policy. By crafting a malicious HTML page, an attacker could exploit this to gain unauthorized access to sensitive information or actions across different web origins.

Отчет

This vulnerability in the WebXR component of chromium-browser is rated as Important. A remote attacker could exploit insufficient policy enforcement to bypass the same-origin policy through a crafted HTML page, potentially leading to unauthorized access to sensitive information. User interaction, such as visiting a malicious website, is required for exploitation.

Дополнительная информация

Статус:

Important
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2509021chromium-browser: Google Chrome: Same-Origin Policy Bypass via Insufficient Policy Enforcement in WebXR

EPSS

Процентиль: 7%
0.00178
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
12 дней назад

Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

CVSS3: 6.5
nvd
12 дней назад

Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

msrc
11 дней назад

Chromium: CVE-2026-17823 Insufficient policy enforcement in WebXR

CVSS3: 6.5
debian
12 дней назад

Insufficient policy enforcement in WebXR in Google Chrome prior to 151 ...

CVSS3: 6.5
github
12 дней назад

Insufficient policy enforcement in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)

EPSS

Процентиль: 7%
0.00178
Низкий

7.1 High

CVSS3