Junglewise Threat Intelligence

CVE-2026-14110: Google Chrome UI spoofing in DarkMode

CVE-2026-14110 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Dark Mode feature could allow a malicious website to misrepresent or 'spoof' parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are interacting with a legitimate browser prompt. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

A UI spoofing vulnerability exists in the Dark Mode implementation of Google Chrome prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate the browser's user interface elements by enticing a user to visit a specially crafted HTML page. While the technical root cause is not fully detailed in the advisory, the impact is limited to visual deception (spoofing) rather than direct code execution or data exfiltration. Google has addressed this issue in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats