Description
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper implementation in Chrome DevTools allows a maliciously crafted extension to perform UI spoofing. The vulnerability, identified as CWE‑451, enables an attacker who persuades a user to install a malicious extension to overlay fake user interface elements, potentially tricking the user into entering sensitive information or accepting actions that would otherwise be disallowed. This weakness does not provide code execution, kernel privilege escalation, or network intrusion; its impact is confined to the visual presentation of the browser UI.

Affected Systems

All users of Google Chrome desktop versions older than 150.0.7871.47 who install extensions are at risk. The flaw is present only in the desktop build up to that specific version and affects the entire set of extensions that run within the Chrome runtime.

Risk and Exploitability

The CVSS score of 4.8 places the vulnerability in the low severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attack execution requires a user to install a malicious extension, typically via social engineering or malicious web content. Based on the description, it is inferred that no special privileges or network access are required; the attack is limited to UI spoofing on the host machine.

Generated by OpenCVE AI on August 1, 2026 at 23:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later to eliminate the flawed DevTools implementation.
  • Drop or remove any extensions that are unknown, unverified, or that request more permissions than necessary for their stated function.
  • Regularly audit the permissions of installed extensions and uninstall those that offer excessive or irrelevant access to the browser UI.

Generated by OpenCVE AI on August 1, 2026 at 23:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Sun, 02 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Extension in Chrome DevTools

Mon, 27 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Tue, 21 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Extension in Chrome DevTools

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Extension in Chrome DevTools

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension
Weaknesses CWE-200

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension
Weaknesses CWE-200

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:48:40.560Z

Reserved: 2026-06-29T23:11:52.670Z

Link: CVE-2026-14154

cve-icon Vulnrichment

Updated: 2026-07-01T01:48:35.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T00:00:14Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information