Junglewise Threat Intelligence

CVE-2026-14131: Google Chrome UI spoofing in WebAppInstalls

CVE-2026-14131 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's web application installation component could allow a malicious website to trick users by spoofing parts of the browser's user interface. This could be used to mislead users into performing unintended actions or trusting a malicious site. Users should update to the latest version of Chrome to mitigate this risk.

Technical details

An improper input validation vulnerability (CWE-20) exists in the WebAppInstalls component of Google Chrome prior to version 150.0.7871.47. A remote attacker who has already compromised the renderer process can exploit this flaw via a specially crafted HTML page to perform UI spoofing. This allows the attacker to manipulate the browser's interface to deceive the user. The vulnerability is rated as Low severity by Chromium and is addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats