Description
Insufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insufficient validation of the PopupBlocker module allowed a remote attacker who has already compromised the browser’s renderer process to craft an HTML page that could spoof the browser’s user interface. The flaw permits presentation of UI elements that appear legitimate. Based on the nature of UI spoofing, it is inferred that this could be used for phishing attacks, but this is not specifically stated in the CVE description. The weakness is a classic input‑validation flaw identified as CWE‑20, and the Chromium release notes classify its severity as low.

Affected Systems

Google Chrome browsers running any version earlier than 150.0.7871.47 are vulnerable. The issue applies to all platforms where the vulnerable renderer component is present, regardless of operating system or device type.

Risk and Exploitability

The flaw can be exploited only after the attacker has already compromised the browser’s renderer process, which represents a low likelihood (EPSS < 1%) and the low CVSS score of 4.3 indicate a low impact under normal circumstances is not listed in CISA’s KEV catalog and no public exploitation has been reported, the current risk to end users is limited, but threats remain if an attacker gains renderer‑level control.

Generated by OpenCVE AI on July 17, 2026 at 13:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 150.0.7871.47 or newer, ensuring the patch that fixes the PopupBlocker input validation flaw is applied.
  • Enable automatic updates so that the latest stable release is installed on all systems.
  • Adjust Chrome’s pop‑up blocking settings (Settings > Privacy and security > Site Settings > Pop‑ups and redirects) to block pop‑ups from untrusted sites, providing a temporary defense if the patch cannot be applied immediately.

Generated by OpenCVE AI on July 17, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Flaw Allows UI Spoofing in Google Chrome

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Flaw Allows UI Spoofing in Google Chrome

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Chrome PopupBlocker Validation Failure Enables UI Spoofing

Mon, 13 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome PopupBlocker Validation Failure Enables UI Spoofing

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title PopupBlocker UI Spoofing Vulnerability in Chrome

Fri, 10 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title PopupBlocker UI Spoofing Vulnerability in Chrome

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Enables UI Spoofing

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Enables UI Spoofing

Tue, 07 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Allows UI Spoofing in Google Chrome

Mon, 06 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Allows UI Spoofing in Google Chrome

Mon, 06 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Insufficient PopupBlocker Input Validation Allowing UI Spoofing

Sun, 05 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Insufficient PopupBlocker Input Validation Allowing UI Spoofing

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Flaw Enabling UI Spoofing via Crafted HTML Pages

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Flaw Enabling UI Spoofing via Crafted HTML Pages

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Weakness Enables UI Spoofing in Chrome

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Weakness Enables UI Spoofing in Chrome

Thu, 02 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Exploit Leading to UI Spoofing in Google Chrome

Thu, 02 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Exploit Leading to UI Spoofing in Google Chrome

Thu, 02 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Allows UI Spoofing in Google Chrome

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Allows UI Spoofing in Google Chrome

Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Issue Allows UI Spoofing in Chrome

Wed, 01 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title PopupBlocker Input Validation Issue Allows UI Spoofing in Chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:44:28.844Z

Reserved: 2026-06-29T23:11:39.904Z

Link: CVE-2026-14089

cve-icon Vulnrichment

Updated: 2026-07-01T14:43:04.472Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T14:00:16Z

Weaknesses
  • CWE-20

    Improper Input Validation