CVE-2026-14381
published 2026-07-01CVE-2026-14381: Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.21%
11.6th percentile
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| chrome | < 150.0.7871.46 | 150.0.7871.46 | |
| chrome | >= 150.0.7871.46 < 150.0.7871.46 | 150.0.7871.46 | |
| chrome_desktop | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for Desktop: CVE-2026-14408
vendor_chrome·2026-06-30
CVE-2026-14408 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-14408
Stable Channel Update for Desktop
CVE-2026-14408: Uninitialized Use in Dawn. Reported by Chrovus on 2026-05-16 [TBD][ 407283320 ] Medium CVE-2026-14381: Incorrect security UI in WebAppInstalls
Reported by Hafiizh on 2025-03-30 [N/A][ 492410546 ] Medium CVE-2026-14383: Inappropriate implementation in V8
Severity: medium
Red Hat
chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
vendor_redhat·2026-06-30·CVSS 6.5
CVE-2026-14381 [MEDIUM] CWE-1021 chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
chromium-browser: chromium-browser: Incorrect security UI in WebAppInstalls
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
An incorrect security ui flaw was found in the WebAppInstalls component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=407283320
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
GHSA
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
ghsa_unreviewed·2026-07-02
CVE-2026-14381 [MEDIUM] CWE-290 Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page.
Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
2026-07-01
Published