Executive brief
A security vulnerability exists in Google Chrome for Android within its Extended Reality (XR) components. By tricking a user into visiting a specially crafted website, a remote attacker could potentially read sensitive information from the device's memory or cause the browser to crash. This could lead to the exposure of private data or a disruption of the browsing experience.
Technical details
A use-after-free vulnerability exists in the XR (Extended Reality) component of Google Chrome for Android. The flaw is triggered when the browser attempts to access memory that has already been deallocated, typically during the processing of a specifically crafted HTML page. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website, leading to an out-of-bounds memory read. This can result in the disclosure of sensitive process memory or potentially be leveraged for further exploitation. The issue is resolved in version 147.0.7727.101.
Affected products
- Google Chrome prior to 147.0.7727.101
Timeline
- 2026-03-30: disclosed: Reported to Chromium by Jihyeon Jeong
- 2026-04-15: patched: Fixed in version 147.0.7727.101
- 2026-04-15: advisory