CVE-2026-14123
published 2026-06-30CVE-2026-14123: Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar)…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.18%
7.8th percentile
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-14410
vendor_chrome·2026-06-30·CVSS 4.3
CVE-2026-14410 [LOW] Stable Channel Update for Desktop: CVE-2026-14410
Stable Channel Update for Desktop
CVE-2026-14410: Inappropriate implementation in Skia. Reported by Google on 2026-05-16 [N/A][ 513856644 ] Low CVE-2026-14123: Incorrect security UI in Chrome for iOS
Reported by Google on 2026-05-16 [N/A][ 513867710 ] Low CVE-2026-14124: Inappropriate implementation in CredentialProvider
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2026-14123
vendor_chrome·2026-06-30
CVE-2026-14123 [LOW] Stable Channel Update for Desktop: CVE-2026-14123
Stable Channel Update for Desktop
CVE-2026-14123: Incorrect security UI in Chrome for iOS. Reported by Google on 2026-05-16 [N/A][ 513867710 ] Low CVE-2026-14124: Inappropriate implementation in CredentialProvider
Reported by Google on 2026-05-16 [N/A][ 513918431 ] Low CVE-2026-14125: Uninitialized Use in ANGLE
Severity: low
Red Hat
chromium-browser: chromium-browser: Incorrect security UI in Chrome for iOS
vendor_redhat·2026-06-30·CVSS 4.3
CVE-2026-14123 [MEDIUM] chromium-browser: chromium-browser: Incorrect security UI in Chrome for iOS
chromium-browser: chromium-browser: Incorrect security UI in Chrome for iOS
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
An incorrect security ui flaw was found in the Chrome for iOS component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=513856644
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
ghsa_unreviewed·2026-07-01
CVE-2026-14123 [MEDIUM] CWE-451 Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.
Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
2026-06-30
Published