Junglewise Threat Intelligence

CVE-2026-14153: Google Chrome UI spoofing in Glic

CVE-2026-14153 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Glic component could allow a remote attacker to trick users into performing unintended actions. By convincing a user to interact with a specially crafted website, an attacker could spoof parts of the browser's user interface. This could lead to users being misled about the security state of a page or being tricked into clicking elements they did not intend to.

Technical details

A UI spoofing vulnerability exists in the Glic component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this by hosting a malicious HTML page and persuading a user to perform specific UI gestures. Successful exploitation allows the attacker to misrepresent the browser's user interface, potentially facilitating further social engineering attacks. The vulnerability is mitigated by the requirement for specific user interaction and is addressed in Chrome version 150.0.7871.47.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory
  • 2026-06-30: patched

References

Related threats