Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 01 Jul 2026 03:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insufficient XML Policy Enforcement Leads to Memory Disclosure in Chrome Android | |
| Weaknesses | CWE-200 |
Wed, 01 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 | |
| Metrics |
cvssV3_1
|
Tue, 30 Jun 2026 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium) | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Chrome
Published:
Updated: 2026-07-01T01:16:55.832Z
Reserved: 2026-06-29T23:04:00.728Z
Link: CVE-2026-13954
Updated: 2026-07-01T01:09:47.973Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-01T02:45:03Z