Junglewise Threat Intelligence

CVE-2026-14140: Google Chrome UI spoofing in Input on Android

CVE-2026-14140 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a mobile web browser used for accessing the internet. A vulnerability in how the browser handles certain web inputs could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or providing sensitive information by mimicking legitimate browser prompts.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Input component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted data, which can be leveraged by a remote attacker who convinces a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI spoofing, potentially misleading the user about the state of the browser or the origin of a prompt. This issue was fixed in version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats