Junglewise Threat Intelligence

CVE-2026-14133: Google Chrome race condition in History Embeddings

CVE-2026-14133 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A race condition in Google Chrome's History Embeddings feature could allow a remote attacker to manipulate the browser's user interface. By tricking a user into visiting a specially crafted website, an attacker could potentially spoof UI elements to deceive the user. This issue primarily impacts the integrity of the browser's visual information but is considered low severity.

Technical details

A race condition (CWE-362) exists within the History Embeddings component of Google Chrome. The vulnerability is triggered when a remote attacker lures a user to a malicious HTML page designed to exploit improper synchronization during concurrent execution. Successful exploitation allows the attacker to perform UI spoofing, potentially misrepresenting browser state or origin information to the user. The issue was addressed in Chrome version 150.0.7871.47 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats