Executive brief
A vulnerability exists in Google Chrome for Android within its WebXR component, which handles virtual and augmented reality content. By tricking a user into visiting a specially crafted website, a remote attacker could access sensitive information stored in the browser's memory. This could lead to the exposure of private data or help an attacker bypass other security protections.
Technical details
An uninitialized use vulnerability (CWE-457) exists in the WebXR component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, leading to the use of memory that has not been properly initialized. A remote, unauthenticated attacker can exploit this to read sensitive information from the browser's process memory. This vulnerability was addressed in version 150.0.7871.47. The attack requires minimal user interaction, typically just visiting a malicious website.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched