Junglewise Threat Intelligence

CVE-2026-14410: Google Chrome UI spoofing in Skia

CVE-2026-14410 · Severity: info · Published 2026-07-01

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its graphics engine, Skia, could allow an attacker who has already partially compromised the browser's internal processes to trick users by spoofing parts of the user interface. This could be used to deceive users into performing unintended actions or revealing information by displaying fraudulent visual elements.

Technical details

An inappropriate implementation vulnerability exists in the Skia graphics library component of Google Chrome. The flaw allows a remote attacker to perform UI spoofing if they have already achieved a compromise of the renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can manipulate the browser's user interface elements. This issue is mitigated by the requirement of a pre-existing renderer compromise, leading to its 'Low' severity rating by Chromium. The vulnerability is addressed in Chrome version 150.0.7871.46.

Affected products

  • Google Chrome prior to 150.0.7871.46

Timeline

  • 2026-06-30: patched: Chrome 151 promoted to stable channel containing the fix.
  • 2026-07-01: disclosed: CVE published.

References

Related threats