Junglewise Threat Intelligence

CVE-2026-8583: Google Chrome for Android insufficient policy enforcement in WebXR

CVE-2026-8583 · Severity: medium · CVSS 5.3 · Published 2026-05-14

Technologies: Google Chrome for Android, Google Android, Google Chrome. Vendors: Google.

Executive brief

A security flaw in Google Chrome for Android's WebXR component—used for virtual and augmented reality experiences—could allow an attacker to access sensitive information. By tricking a user into visiting a specially crafted website, an attacker who has already partially compromised the browser's internal processes could read data from the device's memory. This could lead to the exposure of private user data or browsing information.

Technical details

An information disclosure vulnerability exists in the WebXR component of Google Chrome for Android due to insufficient policy enforcement. The flaw allows a remote attacker to read sensitive information from the browser's process memory. To exploit this, an attacker must first achieve a compromise of the renderer process (e.g., via a separate vulnerability) and then entice a user to visit a malicious HTML page. This chain allows the attacker to bypass memory isolation boundaries within the WebXR implementation. The issue is resolved in version 148.0.7778.168.

Affected products

  • Google Chrome for Android prior to 148.0.7778.168

Timeline

  • 2026-05-12: patched: Stable channel update released for desktop and Android versions.
  • 2026-05-14: disclosed: NVD publication date.

References

Related threats