Description
Inappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation of the PreviewTab feature in Google Chrome for Android allows a remote attacker, through specific on‑screen gestures, to cause the browser to render a crafted HTML page that masquerades as a legitimate user interface. The victim sees counterfeit UI elements appearing within the browser, and this UI spoofing could mislead the user into interacting with malicious content. The vulnerability is identified as CWE‑451 and is rated low severity.

Affected Systems

Google Chrome for Android versions earlier than 150.0.7871.47, specifically the PreviewTab component, are affected.

Risk and Exploitability

The CVSS score of 4.2 places this issue in the low‑severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. Because the vulnerability is absent from the CISA KEV catalog and requires explicit user interaction with precise UI gestures, the likelihood of successful attacks remains low, limiting overall risk.

Generated by OpenCVE AI on July 15, 2026 at 23:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome version 150.0.7871.47 or later on Android devices.
  • Enable automatic updates to receive security patches as soon as they are released.
  • Educate users to avoid performing suspicious UI gestures on untrusted web pages.

Generated by OpenCVE AI on July 15, 2026 at 23:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Chrome Android PreviewTab UI Spoofing Vulnerability

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Page in Google Chrome PreviewTab on Android

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Page in Google Chrome PreviewTab on Android

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing through Inadequate PreviewTab Implementation in Chrome for Android

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing through Inadequate PreviewTab Implementation in Chrome for Android

Wed, 08 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome Android PreviewTab

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome Android PreviewTab

Mon, 06 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Unauthorized UI Spoofing via Crafted HTML in Chrome PreviewTab on Android

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Unauthorized UI Spoofing via Crafted HTML in Chrome PreviewTab on Android

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Android PreviewTab

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome Android PreviewTab

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome PreviewTab on Android

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome PreviewTab on Android

Fri, 03 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome PreviewTab UI Spoofing Vulnerability (Android)

Fri, 03 Jul 2026 02:00:00 +0000

Type Values Removed Values Added
Title Chrome PreviewTab UI Spoofing Vulnerability (Android)

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome Android PreviewTab before 150.0.7871.47

Thu, 02 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML Page in Chrome Android PreviewTab before 150.0.7871.47

Thu, 02 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome Android PreviewTab Allows UI Spoofing via Crafted Page

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chrome Android PreviewTab Allows UI Spoofing via Crafted Page

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Insecure PreviewTab Allows UI Spoofing in Chrome on Android
Weaknesses CWE-1008
CWE-727

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Insecure PreviewTab Allows UI Spoofing in Chrome on Android
Weaknesses CWE-1008
CWE-727

Wed, 01 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:56:47.291Z

Reserved: 2026-06-29T23:11:47.875Z

Link: CVE-2026-14129

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:28.756Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:15:15Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information