Junglewise Threat Intelligence

CVE-2026-14129: Google Chrome for Android UI spoofing in PreviewTab

CVE-2026-14129 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome for Android could allow a malicious website to trick users into performing unintended actions. By convincing a user to perform specific touch gestures, an attacker can spoof parts of the browser's user interface. This could be used to mislead users about the security or origin of the content they are viewing, potentially leading to phishing or other deceptive attacks.

Technical details

A UI spoofing vulnerability exists in the PreviewTab component of Google Chrome on Android prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that fails to properly isolate or validate UI elements during specific user interactions. A remote attacker can exploit this by hosting a specially crafted HTML page and tricking a user into performing specific UI gestures. Successful exploitation allows the attacker to misrepresent the browser's interface, potentially masking the true origin of a site. The issue is addressed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD publication date
  • 2026-06-30: patched: Chrome stable channel update released

References

Related threats