Junglewise Threat Intelligence

CVE-2026-14013: Google Chrome UI spoofing in SVG

CVE-2026-14013 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's handling of Scalable Vector Graphics (SVG) could allow a malicious website to misrepresent its identity or content. By tricking a user into visiting a specially crafted webpage, an attacker could spoof parts of the browser's user interface. This could be used to deceive users into performing unintended actions or disclosing sensitive information by making malicious content appear legitimate.

Technical details

A UI spoofing vulnerability exists in Google Chrome's SVG implementation due to an inappropriate implementation of graphics rendering. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page containing specially crafted SVG content. Successful exploitation allows the attacker to manipulate or spoof elements of the browser's user interface, potentially leading to phishing or other social engineering attacks. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats