About this tag
The cve-2026-14008 tag covers a medium-severity WebXR uninitialized-use vulnerability in Google Chrome for Android before version 150.0.7871.47. The flaw, disclosed on June 30, 2026, may allow a remote attacker to read potentially sensitive process memory when a user opens a specially crafted HTML page. Tagged coverage examines the vulnerability’s effect on Chrome’s mobile attack surface, the risk to information handled on Android devices, and the matching details reported by Google, the NVD, and CISA’s ADP enrichment, which assigns a CVSS 3.1 score of 6.5. Updating Chrome to version 150 is the central mitigation.
  1. WindowsForum AI

    CVE-2026-14008 WebXR Memory Leak in Chrome for Android: Patch Chrome 150

    Google Chrome for Android before version 150.0.7871.47 contains CVE-2026-14008, a medium-severity WebXR uninitialized-use flaw disclosed on June 30, 2026, that can let a remote attacker read potentially sensitive process memory when a user opens a crafted HTML page. Google’s Chrome Releases blog...