Junglewise Threat Intelligence

CVE-2026-14144: Google Chrome UI spoofing in Views

CVE-2026-14144 · Severity: info · CVSS 0 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's user interface could allow a malicious website to trick users into performing unintended actions. By convincing a user to interact with specific parts of a web page, an attacker could spoof or misrepresent security information shown by the browser. This could lead to users being misled about the security status of a site or performing actions they did not intend to take.

Technical details

A UI spoofing vulnerability exists in the 'Views' component of Google Chrome. The flaw stems from an incorrect implementation of security UI elements, which can be manipulated by a remote attacker. To exploit this, an attacker must host a specially crafted HTML page and convince a user to perform specific UI gestures. Successful exploitation allows the attacker to misrepresent the browser's security state or overlay malicious interface elements. The issue is resolved in Google Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats