Description
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from an improper implementation in Chrome DevTools that allows a maliciously crafted extension to perform UI spoofing. The weakness is identified as CWE‑451.

Affected Systems

All users of Google Chrome desktop versions older than 150.0.7871.47 who install extensions are at risk. An attacker who convinces a user to install a malicious extension can trigger this vulnerability.

Risk and Exploitability

The CVSS score of 4.8 places the vulnerability in the low severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attack execution requires a user to install a malicious extension, typically via social engineering. No data indicates that special privileges or network access are required, so the attack is limited to UI spoofing.

Generated by OpenCVE AI on July 17, 2026 at 13:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer to remove the flawed DevTools implementation.
  • Only install extensions from trusted, verified vendors; review and remove any extensions that appear suspicious or have excessive permissions.
  • Consider disabling or uninstalling extensions that are no longer needed or have unclear sources.

Generated by OpenCVE AI on July 17, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Tue, 14 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Mon, 13 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sun, 12 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension

Sat, 11 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Thu, 09 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Wed, 08 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Tue, 07 Jul 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Sun, 05 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Sat, 04 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Sat, 04 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Chrome Extension in DevTools

Fri, 03 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Fri, 03 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Thu, 02 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Thu, 02 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension

Wed, 01 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Extension in Chrome DevTools

Wed, 01 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Malicious Extension in Chrome DevTools

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension
Weaknesses CWE-200

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome DevTools UI Spoofing via Malicious Extension
Weaknesses CWE-200

Wed, 01 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T01:48:40.560Z

Reserved: 2026-06-29T23:11:52.670Z

Link: CVE-2026-14154

cve-icon Vulnrichment

Updated: 2026-07-01T01:48:35.287Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T13:45:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information