Junglewise Threat Intelligence

CVE-2026-14139: Google Chrome UI spoofing in TabStrip

CVE-2026-14139 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue was identified in the Google Chrome web browser's tab management system. An attacker could potentially trick a user into performing specific mouse or touch gestures to misrepresent the browser's user interface. This could lead to UI spoofing, where a user is misled about the website they are visiting or the actions they are taking, potentially resulting in the disclosure of sensitive information.

Technical details

A UI spoofing vulnerability exists in the TabStrip component of Google Chrome. The flaw stems from an inappropriate implementation that fails to correctly handle certain UI states during user interaction. A remote attacker can exploit this by hosting a crafted HTML page and convincing a user to perform specific UI gestures (such as drag-and-drop or specific clicks). Successful exploitation allows the attacker to spoof elements of the browser interface, potentially leading to phishing or other social engineering attacks. The vulnerability is addressed in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats