CVE-2026-14130
published 2026-06-30CVE-2026-14130: Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium…
PriorityP420medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.20%
10.4th percentile
Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.47 | 150.0.7871.47 | |
| chrome | >= 150.0.7871.47 < 150.0.7871.47 | 150.0.7871.47 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-14130
vendor_chrome·2026-07-16
CVE-2026-14130 Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-14130
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-14130
Chrome
Stable Channel Update for Desktop: CVE-2026-14128
vendor_chrome·2026-06-30·CVSS 4.3
CVE-2026-14128 [LOW] Stable Channel Update for Desktop: CVE-2026-14128
Stable Channel Update for Desktop
CVE-2026-14128: Insufficient data validation in Chrome for iOS. Reported by Google on 2026-05-17 [N/A][ 514018024 ] Low CVE-2026-14129: Incorrect security UI in PreviewTab
Reported by Google on 2026-05-17 [N/A][ 514019522 ] Low CVE-2026-14130: Incorrect security UI in Omnibox
Severity: low
Chrome
Stable Channel Update for Desktop: CVE-2026-14129
vendor_chrome·2026-06-30
CVE-2026-14129 [LOW] Stable Channel Update for Desktop: CVE-2026-14129
Stable Channel Update for Desktop
CVE-2026-14129: Incorrect security UI in PreviewTab. Reported by Google on 2026-05-17 [N/A][ 514019522 ] Low CVE-2026-14130: Incorrect security UI in Omnibox
Reported by Google on 2026-05-17 [N/A][ 514020982 ] Low CVE-2026-14131: Insufficient validation of untrusted input in WebAppInstalls
Severity: low
Red Hat
chromium-browser: Incorrect security UI in Omnibox
vendor_redhat·2026-06-30·CVSS 4.3
CVE-2026-14130 [MEDIUM] CWE-1021 chromium-browser: Incorrect security UI in Omnibox
chromium-browser: Incorrect security UI in Omnibox
Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=514019522
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
ghsa_unreviewed·2026-07-01
CVE-2026-14130 [MEDIUM] CWE-451 Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
No detection rules found.
No public exploits indexed.
2026-06-30
Published