Description
Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in Chrome's WebAppInstalls component stems from insufficient validation of untrusted input. The likely attack scenario requires an attacker who has already compromised the renderer process, causing Chrome to display a spoofed user interface. This vulnerability is categorized as CWE‑20 (Improper Input Validation).

Affected Systems

All variants of Google Chrome that use the WebAppInstalls feature and are running a build older than 150.0.7871.47 are vulnerable. The defect exists in the renderer component, which is deployed across all supported operating systems and architectures; there are no platform‑specific limitations noted.

Risk and Exploitability

The CVSS score of 4.3 reflects a low severity level, and the EPSS score of less than 1% indicates a very low probability of exploitation. The likely attack vector is a renderer process already compromised, which limits the practical attack surface. The CVE is not listed in the CISA KEV catalog, further suggesting that the overall risk remains low for systems that apply the available update promptly.

Generated by OpenCVE AI on July 15, 2026 at 10:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Chrome 150.0.7871.47 or newer.
  • Ensure Chrome’s automatic update service is enabled so that updates are applied automatically.
  • Educate users to remain vigilant against unexpected user interface changes during browsing sessions.

Generated by OpenCVE AI on July 15, 2026 at 10:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Chrome WebAppInstalls

Tue, 14 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Chrome WebAppInstalls

Sun, 12 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables UI Spoofing in Chrome WebAppInstalls

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables UI Spoofing in Chrome WebAppInstalls

Thu, 09 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Unsanitized input in Chrome renderer enables UI spoofing

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Unsanitized input in Chrome renderer enables UI spoofing

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebAppInstalls Input Validation Flaw in Google Chrome

Tue, 07 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebAppInstalls Input Validation Flaw in Google Chrome

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome WebAppInstalls

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome WebAppInstalls

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated WebAppInstalls Input in Google Chrome

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated WebAppInstalls Input in Google Chrome

Sat, 04 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome's WebAppInstalls

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome's WebAppInstalls

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Enables UI Spoofing

Thu, 02 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input in Chrome WebAppInstalls Enables UI Spoofing

Thu, 02 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Allows UI Spoofing in Chrome WebAppInstalls

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Allows UI Spoofing in Chrome WebAppInstalls

Wed, 01 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome WebAppInstalls Due to Untrusted Input

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Chrome WebAppInstalls Due to Untrusted Input

Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in WebAppInstalls

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in WebAppInstalls

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:34:22.131Z

Reserved: 2026-06-29T23:11:48.242Z

Link: CVE-2026-14131

cve-icon Vulnrichment

Updated: 2026-07-01T14:45:15.740Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T10:30:05Z

Weaknesses
  • CWE-20

    Improper Input Validation