Executive brief
Google Chrome on Android is a mobile web browser used for accessing the internet. A vulnerability in how the browser handles XML data could allow a malicious website to access sensitive information stored in the application's memory. This could lead to the exposure of private user data or session information if a user visits a specially crafted web page.
Technical details
An information disclosure vulnerability exists in Google Chrome for Android due to insufficient policy enforcement within the XML processing component. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to read potentially sensitive information from the browser's process memory. This issue is categorized by Chromium as Medium severity and was addressed in version 150.0.7871.47. The vulnerability is tracked as CVE-2026-13954.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched: Fixed in version 150.0.7871.47