Description
Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient XML policy enforcement in Google Chrome on Android allows a remote attacker to obtain potentially sensitive information from the browser process memory via a crafted HTML page. The primary impact is the disclosure of confidential data due to a weakness in access control (CWE-284).

Affected Systems

Google Chrome on Android versions earlier than 150.0.7871.47 are affected.

Risk and Exploitability

Based on the description, it is inferred that a remote attacker can exploit the flaw by delivering a crafted HTML page to an Android device. The likely attack vector is web content served to Chrome on Android. No additional privileges are required beyond the user visiting the page. The CVSS score of 6.5 indicates moderate severity, the EPSS score of < 1 % indicates a low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 2, 2026 at 00:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 150.0.7871.47 or later to address the CWE-284 access control flaw in XML policy enforcement.
  • If an update cannot be applied, restrict browsing to trusted sites or use a different browser.
  • Keep the device’s OS updated to the latest security patches to reduce related exploitation risks.

Generated by OpenCVE AI on August 2, 2026 at 00:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Sun, 02 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Enables Remote Information Disclosure in Google Chrome on Android

Wed, 29 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Enables Remote Information Disclosure in Google Chrome on Android

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Insufficient XML Policy Enforcement in Chrome on Android

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Insufficient XML Policy Enforcement in Chrome on Android

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title XML Policy Enforcement Weakness in Chrome on Android Allows Remote Information Disclosure

Tue, 14 Jul 2026 01:15:00 +0000

Type Values Removed Values Added
Title XML Policy Enforcement Weakness in Chrome on Android Allows Remote Information Disclosure

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Remote Information Disclosure in Chrome for Android

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Remote Information Disclosure in Chrome for Android

Thu, 09 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Chrome Android XML Policy Bypass Exposes Process Memory

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome Android XML Policy Bypass Exposes Process Memory

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Android Chrome XML Policy Bypass Allows Memory Disclosure

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Android Chrome XML Policy Bypass Allows Memory Disclosure

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Information Disclosure in Chrome for Android

Sun, 05 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Information Disclosure in Chrome for Android

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via XML Policy Bypass in Chrome Android

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via XML Policy Bypass in Chrome Android

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Enables Information Disclosure in Chrome for Android

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Enables Information Disclosure in Chrome for Android

Fri, 03 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Crafted HTML Page in Google Chrome on Android

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote Information Disclosure via Crafted HTML Page in Google Chrome on Android

Thu, 02 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Sensitive Information Disclosure in Chrome for Android

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Allows Sensitive Information Disclosure in Chrome for Android

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Memory Disclosure via XML Policy Enforcement Flaw in Google Chrome on Android

Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Memory Disclosure via XML Policy Enforcement Flaw in Google Chrome on Android

Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Leads to Memory Disclosure in Chrome Android
Weaknesses CWE-200

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Insufficient XML Policy Enforcement Leads to Memory Disclosure in Chrome Android
Weaknesses CWE-200

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:16:55.832Z

Reserved: 2026-06-29T23:04:00.728Z

Link: CVE-2026-13954

cve-icon Vulnrichment

Updated: 2026-07-01T01:09:47.973Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:30:03Z

Weaknesses