Junglewise Threat Intelligence

CVE-2026-14404: Google Chrome UI spoofing in PDFium

CVE-2026-14404 · Severity: info · CVSS 4.3 · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's PDF viewer (PDFium) could allow a malicious website to trick users by spoofing parts of the browser's user interface. By convincing a user to open a specially crafted PDF file, an attacker could display misleading information or fake prompts. This type of attack is typically used to facilitate phishing or to deceive users into performing unintended actions.

Technical details

A UI spoofing vulnerability exists in the PDFium component of Google Chrome due to an inappropriate implementation of interface elements when rendering PDF documents. A remote, unauthenticated attacker can exploit this by enticing a user to open a specially crafted PDF file. Successful exploitation allows the attacker to misrepresent or overlay portions of the browser's user interface, potentially leading to user confusion or successful social engineering attacks. The issue is addressed in Chrome version 150.0.7871.46 and later.

Affected products

  • Google Chrome Prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 150.0.7871.46 released to stable channel
  • 2026-07-01: advisory: NVD publication date

References

Related threats