Junglewise Threat Intelligence

CVE-2026-14034: Google Chrome WebXR navigation restriction bypass on Android

CVE-2026-14034 · Severity: info · CVSS 2 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to bypass standard navigation restrictions. This occurs within the WebXR component, which handles virtual and augmented reality experiences in the browser. An attacker could use a specially crafted webpage to force the browser to navigate in ways that are normally restricted, potentially leading to unauthorized site transitions or user confusion.

Technical details

A navigation restriction bypass exists in the WebXR implementation of Google Chrome for Android. The vulnerability is classified as an 'Inappropriate Implementation' within the WebXR component, which manages VR/AR content. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger unintended navigation actions that bypass security boundaries. This is rated as Low severity by Chromium. The issue is resolved in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats