SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-78962

MEDIUM · CVSS 4.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

A vulnerability in the WebXR component of Google Chrome prior to version 152.0.7977.65 allows remote attackers to exploit uninitialized resources, potentially leading to the leakage of cross-origin data through specially crafted HTML pages. This issue poses a medium security risk, particularly for organizations that utilize WebXR applications or rely on Chrome for web-based operations. Users and administrators should prioritize updating their Chrome installations to mitigate the risk of data exposure.

CVE
CVE-2026-78962
Severity
MEDIUM
CVSS
4.3
EPSS
0.26%
Chrome

Original NVD Description

Uninitialized resource in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)

Related CVEs

Other vulnerabilities affecting the same vendor(s)