Executive brief
Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in its WebXR component, which handles virtual and augmented reality content, could allow a malicious website to access sensitive information from the device's memory. This could potentially lead to the exposure of private data while browsing.
Technical details
A vulnerability classified as 'Uninitialized Use' (CWE-457) exists in the WebXR component of Google Chrome for Android. The flaw is triggered when the browser processes a specially crafted HTML page, allowing a remote attacker to read uninitialized memory. This can result in the leakage of sensitive information from the browser's process memory. The issue was addressed in version 151.0.7922.72. Exploitation requires the victim to visit a malicious website, but no special privileges are required by the attacker.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released
- 2026-07-30: disclosed: NVD publication date