CVE-2026-14114
published 2026-06-30CVE-2026-14114: Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.17%
6.8th percentile
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file.
ghsa_unreviewed·2026-07-01
CVE-2026-14114 [HIGH] CWE-451 Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file.
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Chrome
Stable Channel Update for Desktop: CVE-2026-14112
vendor_chrome·2026-06-30·CVSS 5.3
CVE-2026-14112 [LOW] Stable Channel Update for Desktop: CVE-2026-14112
Stable Channel Update for Desktop
CVE-2026-14112: Inappropriate implementation in Enterprise. Reported by Google on 2026-05-16 [N/A][ 513737335 ] Low CVE-2026-14113: Use after free in Updater
Reported by Google on 2026-05-16 [N/A][ 513743129 ] Low CVE-2026-14114: Inappropriate implementation in WebAppInstalls
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2026-14114
vendor_chrome·2026-06-30
CVE-2026-14114 [LOW] Stable Channel Update for Desktop: CVE-2026-14114
Stable Channel Update for Desktop
CVE-2026-14114: Inappropriate implementation in WebAppInstalls. Reported by Google on 2026-05-16 [N/A][ 513745699 ] Low CVE-2026-14115: Insufficient validation of untrusted input in Cast
Reported by Google on 2026-05-16 [N/A][ 513747800 ] Low CVE-2026-14116: Insufficient validation of untrusted input in DevTools
Severity: low
Red Hat
chromium-browser: Inappropriate implementation in WebAppInstalls
vendor_redhat·2026-06-30·CVSS 7.5
CVE-2026-14114 [HIGH] CWE-1021 chromium-browser: Inappropriate implementation in WebAppInstalls
chromium-browser: Inappropriate implementation in WebAppInstalls
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
An inappropriate implementation flaw was found in the WebAppInstalls component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513743129
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
bugzilla·2026-07-01·CVSS 7.5
CVE-2026-14114 [HIGH] CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
CVE-2026-14114 chromium-browser: Inappropriate implementation in WebAppInstalls
Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (Chromium security severity: Low)
Wiz
CVE-2025-14114 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.4
CVE-2025-14114 [MEDIUM] CVE-2025-14114 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-14114 :
WordPress vulnerability analysis and mitigation
The 1180px Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class' shortcode attribute in all versions up to, and including, 1.1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Source : NVD
## 6.4
Score
Published January 7, 2026
Severity MEDIUM
CNA Score 6.4
Affected Technologies
WordPress
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 2.7
Exploitation Probability (EPSS) N/A
2026-06-30
Published