Junglewise Threat Intelligence

CVE-2026-13947: Google Chrome uninitialized use in XR

CVE-2026-13947 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's XR (Extended Reality) component could allow a malicious website to access sensitive information from the browser's memory. This occurs if an attacker first compromises the browser's rendering process and then lures a user to a specially crafted webpage. Successful exploitation could lead to the exposure of private data belonging to the user or other open browser tabs.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the XR component of Google Chrome. The flaw allows a remote attacker to read sensitive information from the process memory. To exploit this, an attacker must first achieve code execution within a compromised renderer process and then entice a user to visit a malicious HTML page. This memory leak can be used to bypass security mitigations or harvest sensitive data. The issue is resolved in Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched: Fixed in version 150.0.7871.47

References

Related threats