Junglewise Threat Intelligence

CVE-2026-14030: Google Chrome SplitView URL spoofing on Linux

CVE-2026-14030 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Linux could allow a malicious website to trick users into believing they are visiting a legitimate site. By convincing a user to perform specific interface gestures, an attacker can manipulate the address bar to display a fake URL. This could be used in phishing attacks to steal sensitive information by mimicking trusted websites.

Technical details

A URL spoofing vulnerability exists in the SplitView component of Google Chrome for Linux. The flaw stems from an inappropriate implementation that fails to correctly update or protect the Omnibox (address bar) state during specific user interface gestures. A remote attacker can exploit this by hosting a specially crafted HTML page and social engineering a user into performing specific interactions. Successful exploitation allows the attacker to display a fraudulent URL in the address bar while the browser displays malicious content, facilitating phishing. The issue is resolved in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats