Junglewise Threat Intelligence

CVE-2026-14002: Google Chrome UI spoofing in Geolocation

CVE-2026-14002 · Severity: info · CVSS 5.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's geolocation component could allow a remote attacker to deceive users by spoofing parts of the browser's user interface. This could be used to trick users into granting permissions or performing actions they did not intend. To exploit this, an attacker would first need to compromise the browser's rendering process, typically by enticing a user to visit a malicious website.

Technical details

An inappropriate implementation vulnerability exists in the Geolocation component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform UI spoofing. By utilizing a specially crafted HTML page, the attacker can manipulate browser interface elements related to geolocation. This could lead to unauthorized permission grants or other user-deception attacks. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats