Junglewise Threat Intelligence

CVE-2026-14077: Google Chrome Omnibox spoofing in Select on macOS

CVE-2026-14077 · Severity: info · CVSS 3.1 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for macOS could allow a malicious website to display a fake web address in the browser's URL bar. This type of flaw is typically used in phishing attacks to trick users into believing they are visiting a legitimate site, such as a bank or email provider, when they are actually on a fraudulent page. Users are advised to update their browser to the latest version to prevent this spoofing.

Technical details

An inappropriate implementation in the 'Select' component of Google Chrome on macOS allowed a remote attacker to spoof the contents of the Omnibox (URL bar). By enticing a user to visit a specially crafted HTML page, an attacker could manipulate the displayed URL to facilitate phishing or social engineering attacks. The vulnerability is specific to the Mac platform and was addressed in version 150.0.7871.47. Chromium developers classified this as a Low severity issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats