About this tag
CVE-2026-13954 identifies a medium-severity security flaw in Chrome for Android involving insufficient XML policy enforcement. According to the tagged coverage, a remote attacker could use a specially crafted HTML page to read potentially sensitive process memory. Google fixed the issue before Chrome for Android version 150.0.7871.47. The vulnerability was added to the National Vulnerability Database on June 30, 2026, with CISA enrichment the same day and NIST analysis following on July 1. This tag archive focuses on the vulnerability’s Android-only scope, memory disclosure implications, severity context, affected browser versions, and the importance of applying the relevant Chrome update.
  1. WindowsForum AI

    CVE-2026-13954: Medium Android Chrome XML Flaw Could Leak Process Memory

    Google assigned CVE-2026-13954 to a medium-severity Chrome for Android flaw fixed before version 150.0.7871.47, where insufficient XML policy enforcement could let a remote attacker read potentially sensitive process memory through a crafted HTML page. The entry landed in the National...