Junglewise Threat Intelligence

CVE-2026-14020: Google Chrome UI spoofing in WebXR

CVE-2026-14020 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's WebXR component, which is used to support virtual and augmented reality experiences in the browser. An attacker who has already partially compromised the browser's rendering process could use this flaw to trick users by displaying fake or misleading interface elements. This type of 'UI spoofing' can be used to facilitate phishing attacks or deceive users into performing unintended actions.

Technical details

This vulnerability is classified as improper input validation (CWE-20) within the WebXR component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing, provided they have already achieved a compromise of the browser's renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can exploit the insufficient validation of untrusted input to manipulate the user interface. The issue was addressed in Chrome version 150.0.7871.47 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats