Description
Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability originates from an unsafe implementation in Chromium’s Paint component. A malicious web page can instruct the browser to render a fabricated user interface element that looks legitimate, tricking the user into interacting with it. The flaw falls under CWE-451, describing an inappropriate implementation that allows an attacker to spoof UI objects. Consequently, a user could be deceived into opening or submitting information, potentially leading to phishing or deceptive transactions.

Affected Systems

All desktop releases of Google Chrome before version 150.0.7871.47, regardless of operating system, contain the Paint component that is affected. System administrators should examine any Chrome instances still running a Version earlier than 150.0.7871.47 for potential exposure.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity. An EPSS score of less than 1% shows that, at the moment, exploitation is unlikely. The vulnerability is not in the CISA KEV catalog, and there are no known public exploits in the CVE record. Attack requires a specially crafted HTML page delivered to an end‑user; only a user who views that page and interacts with the spoofed UI could be harmed. No remote code execution or system compromise is possible. Organizations should treat it as a moderate risk until a patch is available.

Generated by OpenCVE AI on July 17, 2026 at 14:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to 150.0.7871.47 or later, which resolves the Paint component flaw.
  • Where an upgrade cannot be applied immediately, educate users to verify the authenticity of pop‑ups and prompt elements before interacting, especially when browsing unfamiliar sites.
  • Regularly monitor Chrome’s release notes or Google’s security update feed and install any updates that address the Paint component as soon as they become available.

Generated by OpenCVE AI on July 17, 2026 at 14:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Paint Component UI Spoofing Vulnerability

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chromium Paint UI Spoofing Vulnerability

Tue, 14 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Chromium Paint UI Spoofing Vulnerability

Mon, 13 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome Paint UI Spoofing via Crafted HTML

Sun, 12 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Paint UI Spoofing via Crafted HTML

Sat, 11 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Paint

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Paint

Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Paint Component UI Spoofing Vulnerability in Google Chrome

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Paint Component UI Spoofing Vulnerability in Google Chrome

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Sun, 05 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Paint component UI spoofing flaw in Google Chrome

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Paint component UI spoofing flaw in Google Chrome

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Thu, 02 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Paint Component UI Spoofing in Chrome Before 150.0.7871.47

Thu, 02 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Paint Component UI Spoofing in Chrome Before 150.0.7871.47

Thu, 02 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Wed, 01 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Paint Component in Google Chrome

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Chrome Paint UI Spoofing via Crafted HTML
Weaknesses CWE-965

Wed, 01 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Chrome Paint UI Spoofing via Crafted HTML
Weaknesses CWE-965

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:37:44.418Z

Reserved: 2026-06-29T23:04:18.449Z

Link: CVE-2026-14014

cve-icon Vulnrichment

Updated: 2026-07-01T14:37:39.232Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:15:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information