Junglewise Threat Intelligence

CVE-2026-14031: Google Chrome UI spoofing in File Input

CVE-2026-14031 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's file input handling could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by misrepresenting what is being displayed on the screen. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in Google Chrome prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation within the File Input component. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof the browser's user interface, potentially leading to user confusion or social engineering attacks. The vulnerability is classified as Low severity by Chromium. A fix is available in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats