Junglewise Threat Intelligence

CVE-2026-14142: Google Chrome UI spoofing in Extensions

CVE-2026-14142 · Severity: info · CVSS 3.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's extension system could allow a remote attacker to trick users by spoofing parts of the browser's user interface. This occurs if an attacker has already partially compromised the browser's rendering process, allowing them to display deceptive content that appears to be a legitimate part of the browser. Such an attack could be used to facilitate phishing or mislead users into performing unintended actions.

Technical details

An inappropriate implementation vulnerability exists in the Extensions component of Google Chrome. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform UI spoofing. By utilizing a specially crafted HTML page, the attacker can manipulate interface elements to deceive the user. This vulnerability is categorized by Chromium as 'Low' severity and requires the precondition of a compromised renderer. The issue is resolved in Google Chrome version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats