Junglewise Threat Intelligence

CVE-2026-14154: Google Chrome UI spoofing in DevTools

CVE-2026-14154 · Severity: info · CVSS 2 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's developer tools could allow a malicious browser extension to trick users by spoofing parts of the browser's interface. To exploit this, an attacker must first convince a user to install a specifically crafted malicious extension. While the impact is limited to visual deception, it could be used as part of a broader social engineering attack to mislead users about the browser's state or settings.

Technical details

A UI spoofing vulnerability exists in the DevTools component of Google Chrome due to an inappropriate implementation. An attacker can exploit this by convincing a user to install a malicious Chrome extension containing a crafted payload. Once installed, the extension can manipulate or spoof elements of the browser's user interface, potentially leading to user confusion or facilitating further social engineering. This issue is resolved in Google Chrome version 150.0.7871.47 and later. The vulnerability is classified as Low severity by Chromium developers.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: NVD and Chrome Release blog published the vulnerability details.
  • 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.

References

Related threats