Description
Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from inadequate validation of untrusted network input in Chrome’s Network component. An attacker who has already gained control of the renderer process can serve a crafted HTML page that displays a spoofed user interface; the result is a deceptive UI that may cause users to interact with content they believe to be legitimate, potentially creating confusion or unintended actions.

Affected Systems

Google Chrome browsers running versions earlier than 150.0.7871.47 are affected.

Risk and Exploitability

The CVSS score of 4.3 classifies the issue as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first compromise the renderer process; after that, a malicious HTML page can be used for UI spoofing. Consequently, the attack vector is not purely remote and would occur only when the attacker can execute malicious code within the browser environment.

Generated by OpenCVE AI on July 15, 2026 at 23:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer.
  • Restrict or disable third‑party extensions that could compromise the renderer through enterprise policy settings.
  • Implement content‑security policies or browser flags that prevent unauthorized UI injection when the vulnerable Chrome version is in use.

Generated by OpenCVE AI on July 15, 2026 at 23:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Network Input in Chrome Enables UI Spoofing

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Failure Enables UI Spoofing in Chrome

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Failure Enables UI Spoofing in Chrome

Sat, 11 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome Network

Fri, 10 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome Network

Thu, 09 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Network Component Enables UI Spoofing

Wed, 08 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input in Chrome Network Component Enables UI Spoofing

Tue, 07 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Enables UI Spoofing in Chrome

Mon, 06 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Enables UI Spoofing in Chrome

Mon, 06 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Network Enables UI Spoofing

Sun, 05 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome Network Enables UI Spoofing

Sun, 05 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Improper Input Validation in Chrome Network Component

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Improper Input Validation in Chrome Network Component

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Flaw in Chrome Network Enables UI Spoofing

Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Flaw in Chrome Network Enables UI Spoofing

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Untrusted Input Allows UI Spoofing in Google Chrome

Thu, 02 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Untrusted Input Allows UI Spoofing in Google Chrome

Thu, 02 Jul 2026 14:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables UI Spoofing in Chrome

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation Enables UI Spoofing in Chrome

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Improper Input Validation

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Improper Input Validation

Wed, 01 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome Network Layer

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome Network Layer

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:33:45.588Z

Reserved: 2026-06-29T23:11:49.011Z

Link: CVE-2026-14135

cve-icon Vulnrichment

Updated: 2026-07-01T14:51:19.969Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:15:15Z

Weaknesses
  • CWE-20

    Improper Input Validation