Junglewise Threat Intelligence

CVE-2026-14141: Google Chrome domain spoofing in Document Picture-in-Picture

CVE-2026-14141 · Severity: info · CVSS 3.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android could allow a malicious website to misrepresent its identity. By exploiting a flaw in the 'Document Picture-in-Picture' feature, an attacker could trick users into believing they are interacting with a different, trusted website. This type of spoofing is often used in phishing attacks to steal sensitive information or credentials.

Technical details

A domain spoofing vulnerability exists in Google Chrome for Android prior to version 150.0.7871.47. The flaw is rooted in the 'Document Picture-in-Picture' component, where the security UI fails to correctly display or enforce the origin of the window. A remote attacker can leverage a specially crafted HTML page to trigger this incorrect UI state. If successful, the attacker can perform domain spoofing, potentially leading to user confusion or successful phishing attempts. The vulnerability is classified by Chromium as Low severity and has been addressed in the stable channel update.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats