Description
Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation of SVG in Google Chrome prior to version 150.0.7871.47 (CWE‑451) allows a remote attacker to create a crafted HTML page that causes the browser to render user interface elements that closely mimic native Chrome dialogs or controls. The deception is limited to the browser’s UI layer; based on the description, it is inferred that no direct code execution or data exfiltration is achieved by the flaw itself.

Affected Systems

Affected systems are Google Chrome desktop clients on Windows, macOS, and Linux running a stable‑channel build earlier than 150.0.7871.47; the inference about supported operating systems is based on typical Chrome deployment and is not explicitly stated in the CVE description.

Risk and Exploitability

The CVSS score of 4.3 indicates a medium severity rating, and the EPSS score of <1% shows a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Based on the description, it is inferred that exploitation requires only that a victim load a crafted web page in the browser, with no elevated privileges or additional conditions needed. While the impact is confined to UI deception, it is inferred that the vulnerability could enable social engineering attacks driven by the misleading interface.

Generated by OpenCVE AI on July 17, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later.
  • If an immediate update cannot be performed, deploy an enterprise policy that blocks or restricts untrusted SVG content from external origins.
  • Encourage users to verify the authenticity of unexpected prompts or form fields before providing information.

Generated by OpenCVE AI on July 17, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title SVG Rendering UI Spoofing Vulnerability in Google Chrome

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome SVG Rendering UI Spoofing Vulnerability

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chrome SVG Rendering UI Spoofing Vulnerability

Mon, 13 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted SVG Rendering in Google Chrome

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted SVG Rendering in Google Chrome

Fri, 10 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malformed SVG Rendering in Google Chrome

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malformed SVG Rendering in Google Chrome

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome SVG Rendering Enables UI Spoofing Vulnerability

Tue, 07 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome SVG Rendering Enables UI Spoofing Vulnerability

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted SVG Rendering in Google Chrome

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted SVG Rendering in Google Chrome

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via SVG Rendering in Google Chrome

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via SVG Rendering in Google Chrome

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title SVG Rendering UI Spoofing in Google Chrome Allows Remote Attacker to Trick Users

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title SVG Rendering UI Spoofing in Google Chrome Allows Remote Attacker to Trick Users

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Inappropriate SVG implementation in Google Chrome allows malicious UI spoofing via crafted HTML

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Inappropriate SVG implementation in Google Chrome allows malicious UI spoofing via crafted HTML

Thu, 02 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Title SVG UI Spoofing Vulnerability in Google Chrome

Thu, 02 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title SVG UI Spoofing Vulnerability in Google Chrome

Thu, 02 Jul 2026 00:30:00 +0000

Type Values Removed Values Added
Title Inappropriate SVG Rendering Leads to UI Spoofing in Google Chrome
Weaknesses CWE-749

Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Inappropriate SVG Rendering Leads to UI Spoofing in Google Chrome
Weaknesses CWE-749

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Improper SVG Rendering in Chrome
Weaknesses CWE-200

Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Improper SVG Rendering in Chrome
Weaknesses CWE-200

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:16:18.862Z

Reserved: 2026-06-29T23:04:18.208Z

Link: CVE-2026-14013

cve-icon Vulnrichment

Updated: 2026-07-01T14:16:10.365Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information