Description
Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation in Chrome’s TabStrip allowed a remote attacker who could convince a user to perform specific UI gestures to carry out UI spoofing via a crafted HTML page. This weakness corresponds to CWE‑451. The attacker can make the user believe they are interacting with a trustworthy interface while the content is actually a malicious surrogate, potentially leading to phishing, clickjacking or other social‑engineering attacks. The vulnerability does not provide direct code execution or data exfiltration, but it undermines user trust and could enable broader exploitation if coupled with other weaknesses.

Affected Systems

Google Chrome versions prior to 150.0.7871.47 are vulnerable. The affected product is Chrome; any version before the patched release for the stable channel is at risk.

Risk and Exploitability

The CVE is scored as low severity and is not listed in the CISA KEV catalog. Its CVSS score is 4.2. EPSS is not available, indicating no known widespread exploitation. The attack requires the user to be presented with a crafted page and to perform specific gestures, making the exploit opportunistic and user‑dependent. As a result, the probability of exploitation is considered limited, but the impact on user perception and potential for social engineering should not be ignored.

Generated by OpenCVE AI on July 1, 2026 at 13:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 150.0.7871.47 or later
  • Enable automatic updates to ensure timely receipt of security patches
  • Educate users on avoiding suspicious pages or unexpected gesture prompts that could signal UI spoofing activity

Generated by OpenCVE AI on July 1, 2026 at 13:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title Chrome TabStrip UI Spoofing Vulnerability

Wed, 01 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted UI Gestures in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted UI Gestures in Chrome
Weaknesses CWE-79

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:56:17.633Z

Reserved: 2026-06-29T23:11:49.764Z

Link: CVE-2026-14139

cve-icon Vulnrichment

Updated: 2026-07-01T01:52:24.651Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-01T13:30:15Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information