Junglewise Threat Intelligence

CVE-2026-14008: Google Chrome WebXR uninitialized use in Android

CVE-2026-14008 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome for Android within its WebXR component, which handles virtual and augmented reality content. By tricking a user into visiting a specially crafted website, a remote attacker could access sensitive information stored in the browser's memory. This could lead to the exposure of private data or help an attacker bypass other security protections.

Technical details

An uninitialized use vulnerability (CWE-457) exists in the WebXR component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of memory that has not been properly initialized. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This vulnerability was addressed in version 150.0.7871.47. The attack requires minimal user interaction, typically just visiting a malicious website.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats