Junglewise Threat Intelligence

CVE-2026-14126: Google Chrome for Android domain spoofing in security UI

CVE-2026-14126 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome for Android is a mobile web browser used to access the internet. A vulnerability in the browser's user interface could allow a malicious website to misrepresent its identity, making it appear as a different, trusted website. This could be used in phishing attacks to trick users into providing sensitive information like login credentials or financial details.

Technical details

A domain spoofing vulnerability exists in Google Chrome for Android prior to version 150.0.7871.47 due to an incorrect security UI implementation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent the origin of the content (domain spoofing), potentially facilitating phishing or other social engineering attacks. The vulnerability is classified by Chromium as Low severity. Users are advised to update to version 150.0.7871.47 or later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats