PT-2026-41112 · Google · Chrome On Android
Published
2026-05-14
·
Updated
2026-05-16
·
CVE-2026-8583
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome on Android versions prior to 148.0.7778.168
Description
Insufficient policy enforcement in WebXR allows a remote attacker who has compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page.
Recommendations
Update Google Chrome on Android to version 148.0.7778.168 or later.
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chrome On Android