Junglewise Threat Intelligence

CVE-2026-13910: Google Chrome WebXR cross-origin data leak on Android

CVE-2026-13910 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to access data from other websites. This occurs due to a flaw in WebXR, the technology used for virtual and augmented reality experiences in the browser. An attacker could exploit this by tricking a user into visiting a specially crafted webpage, potentially leading to the unauthorized disclosure of sensitive information.

Technical details

An information disclosure vulnerability exists in the WebXR component of Google Chrome for Android. The flaw is caused by insufficient policy enforcement, which fails to properly isolate data across different origins. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass cross-origin restrictions and leak sensitive data from other sites. This issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats