Description
Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in the WebAppInstalls feature of Google Chrome for Windows permits a remote attacker, by tricking a user into executing defined UI gestures on a malicious web page, to perform UI spoofing. This flaw does not grant code execution or direct data theft; it merely allows manipulation of the interface to mimic legitimate prompts or buttons, potentially misleading the user. The vulnerability is categorized under CWE‑451 and carries a CVSS score of 4.2, indicating limited impact and a requirement for user interaction.

Affected Systems

Windows installations of Google Chrome with a build before version 150.0.7871.47 are affected. Any user running any of these historical builds could be vulnerable – versions newer than 150.0.7871.47 contain the fix.

Risk and Exploitability

Exploitation requires an attacker to host a malicious page and persuade the user to perform specific gestures, such as clicking or swiping. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, no widespread exploitation trends are known. The CVSS rating of 4.2 and lack of publicly documented exploits suggest a moderate threat level, mainly limited to targeted phishing or social engineering efforts. Updating the browser or disabling the Web App Installs feature mitigates the risk.

Generated by OpenCVE AI on July 1, 2026 at 13:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to apply the official fix.
  • If an update is not feasible, disable the Web App Installs feature via chrome://flags by setting the flag to "Disabled".
  • Inform users about the risk of deceptive install prompts and advise them to verify unexpected UI changes before performing gestures.

Generated by OpenCVE AI on July 1, 2026 at 13:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malformed Web App Install Flow in Google Chrome for Windows

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebAppInstalls in Google Chrome on Windows UI Spoofing via Malformed Web App Install Flow in Google Chrome for Windows

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebAppInstalls in Google Chrome on Windows

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:56:32.198Z

Reserved: 2026-06-29T23:11:49.590Z

Link: CVE-2026-14138

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:26.704Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T13:30:15Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information