Description
Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input within the Input component of Google Chrome on Android allows an attacker to deliver a crafted HTML page that modifies the UI. The resulting UI spoofing can deceive users into interacting with deceptive elements, and based on the description it is inferred that this could enable phishing or other social‑engineering attacks. The weakness is a classic input validation flaw (CWE‑20).

Affected Systems

Google Chrome for Android releases prior to version 150.0.7871.47 are affected. Users running those versions are vulnerable until they upgrade to the patched build.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote: a malicious web page containing crafted HTML must be viewed by a victim, with no additional privileges or device compromise required.

Generated by OpenCVE AI on July 15, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome for Android 150.0.7871.47 or later to apply the vendor fix.
  • Enable Safe Browsing and consider installing an anti‑phishing extension to detect malicious sites that could exploit UI spoofing.
  • Avoid visiting unknown or suspicious web pages that may serve crafted HTML designed to spoof the interface.

Generated by OpenCVE AI on July 15, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Chrome on Android

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Input Validation in Chrome for Android

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Input Validation in Chrome for Android

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Android UI Spoofing via Untrusted Input Validation

Thu, 09 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title Google Chrome Android UI Spoofing via Untrusted Input Validation

Thu, 09 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Input Validation in Google Chrome for Android

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Input Validation in Google Chrome for Android

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Validation in Google Chrome for Android

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Insufficient Validation in Google Chrome for Android

Mon, 06 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Chrome Android

Mon, 06 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Chrome Android

Sun, 05 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input Enables UI Spoofing in Chrome for Android

Sun, 05 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Enables UI Spoofing in Chrome for Android

Sat, 04 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Untrusted Input in Chrome on Android

Sat, 04 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability via Untrusted Input in Chrome on Android

Fri, 03 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Google Chrome for Android

Fri, 03 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Unvalidated Input in Google Chrome for Android

Thu, 02 Jul 2026 08:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Leading to UI Spoofing in Chrome for Android

Thu, 02 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Leading to UI Spoofing in Chrome for Android

Wed, 01 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome for Android

Wed, 01 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome for Android

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:33:27.378Z

Reserved: 2026-06-29T23:11:49.947Z

Link: CVE-2026-14140

cve-icon Vulnrichment

Updated: 2026-07-01T14:57:03.593Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:15:15Z

Weaknesses
  • CWE-20

    Improper Input Validation