CVE-2026-14042: Google Chrome Isolated Web Apps UI Spoofing Vulnerability
A vulnerability in Google Chrome's Isolated Web Apps feature allows attackers to deceive users through visual manipulation. By sending a specially crafted HTML page, an attacker can spoof the browser's user interface—for example, making a fake login prompt or warning appear legitimate. The attacker cannot steal data or crash the browser, but can trick users into performing actions they wouldn't normally take. This affects Chrome versions before 150.0.7871.47.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-451
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-02
NVD description (verbatim)
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-14042 stems from an inappropriate implementation in Isolated Web Apps (IWA), a Chrome sandbox feature designed to run web applications with enhanced security isolation. The vulnerability exists in how the browser renders UI elements within this isolated context, creating an opportunity for UI spoofing attacks. An attacker-controlled crafted HTML page, served remotely without requiring special privileges, can manipulate the visual presentation in a way that misleads users. The issue is classified under CWE-451 (User Interface Errors and Assumptions), reflecting the mismatch between what the user perceives and the actual state of the application. Exploitation requires user interaction—the victim must view and potentially interact with the malicious page—but the barrier to delivery is low given the attack surface is any website the user visits.
Business impact
UI spoofing attacks targeting Chrome users can lead to credential theft, social engineering attacks, or unauthorized transactions. Users of Isolated Web Apps—commonly used for productivity and communication applications installed from the Chrome Web Store—face an elevated risk of being manipulated into disclosing sensitive information or approving unwanted actions. For organizations deploying Chrome-based web applications, this vulnerability could enable attackers to bypass user trust mechanisms, potentially affecting employee security posture and triggering downstream credential compromise incidents.
Affected systems
Google Chrome versions prior to 150.0.7871.47 are affected. This includes all platforms where Chrome runs: Windows, macOS, Linux, iOS, and Android. Organizations should inventory Chrome deployments and automatic update settings. Users on auto-update will eventually receive the patch, but those on delayed or manual update schedules remain exposed until they upgrade.
Exploitability
Exploitability is relatively straightforward: no special vulnerability details or zero-day tooling are required. An attacker needs only to host a malicious HTML page and trick a user into visiting it (via phishing, watering-hole, or social engineering). The user does not need to install anything or grant unusual permissions; merely viewing the page in Chrome exposes them to the spoofing. However, the attack is limited by the requirement for user interaction and the fact that only Isolated Web Apps are vulnerable, not all Chrome web content. The CVSS 4.3 score reflects low attack complexity but restricted impact (integrity only, no confidentiality or availability loss).
Remediation
Upgrade Google Chrome to version 150.0.7871.47 or later. For organizations managing Chrome via group policy, MDM solutions, or enterprise deployment tools, configure auto-update policies to ensure all devices receive the patch promptly. End-users on personal devices should enable automatic updates if not already active. No workarounds are documented; patching is the sole remediation path.
Patch guidance
Verify that Chrome auto-update is enabled by navigating to chrome://settings/help, which will display the current version and initiate updates if needed. Enterprise administrators should push version 150.0.7871.47 or later through their deployment tools and confirm rollout completion within 30 days. Test the patch on a representative sample of systems before full deployment to ensure compatibility with internal web applications and extensions. Monitor Chrome Web Store for any deprecated or incompatible Isolated Web Apps after patching.
Detection guidance
Detect Isolated Web Apps in use within your environment by auditing Chrome user profiles and the Chrome Web Store extension/app installation logs. Monitor for unusual HTML rendering or spoofing attempts through endpoint detection and response (EDR) tools if available, though this threat is largely preventive (patch-focused) rather than detective. Review browser logs for visits to suspicious or unexpected domains, particularly if users report seeing unusual prompts or warnings. In incident investigations, correlate Chrome version information with timeline of user-reported UI anomalies.
Why prioritize this
Although marked as Low severity by Chromium and scoring CVSS 4.3 (Medium), this vulnerability merits prompt patching because UI spoofing is a proven attack vector for social engineering and credential theft. Isolated Web Apps are increasingly used in enterprise environments for internally-developed and third-party productivity applications, expanding the attack surface. The ease of exploitation (remote, no special privileges) and reliance on user trust make this a higher business risk than the CVSS score alone suggests. Organizations should treat this as a standard-priority patch cycle item, not a deferred update.
Risk score, explained
The CVSS 4.3 score (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N) reflects: Network-accessible attack vector with low complexity, no privileges required, but user interaction needed; integrity impact (UI manipulation) without confidentiality or availability loss. The score is appropriate from a technical standpoint but understates organizational risk because UI spoofing's effectiveness depends heavily on human factors—victim credibility and perceived urgency—rather than pure technical exploitability. For security decision-making, elevate the business priority beyond the numerical score.
Frequently asked questions
Are users of standard Chrome web pages at risk, or only Isolated Web Apps?
Only Isolated Web Apps are affected. These are packaged applications downloaded from the Chrome Web Store and run in an enhanced security sandbox. Regular web pages viewed in standard Chrome tabs are not vulnerable to this specific issue. However, users may not easily distinguish between IWAs and regular web content, so awareness training is recommended.
Does auto-update in Chrome cover this patch automatically?
Yes, if auto-update is enabled (the default on most systems), Chrome will fetch version 150.0.7871.47 or later automatically. Users may need to relaunch the browser to complete the update. Enterprise environments can verify deployment status through admin consoles.
Is this vulnerability actively being exploited in the wild?
As of the publication date, there is no evidence that this vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, nor public reports of active exploitation. However, the low barrier to exploitation means threat actors could develop proof-of-concept code relatively easily, so prompt patching remains prudent.
Can an attacker steal passwords or files using this UI spoofing attack?
UI spoofing itself does not directly extract data or files. The attack works by deceiving the user into voluntarily entering information (e.g., credentials) into a fake form or clicking a malicious link. The attacker relies on social engineering, not technical data exfiltration. Defense-in-depth strategies such as password managers, multi-factor authentication, and user security awareness reduce the impact of successful spoofing attacks.
This analysis is provided for informational purposes to help security teams prioritize patching and risk management. The technical details and remediation guidance are based on the publicly disclosed CVE description and CVSS assessment as of the publication date. For the most current patch status, advisory details, and compatibility information, refer to the official Google Chrome security advisory and release notes. Patch versions, KEV status, and active exploitation information should be independently verified against authoritative vendor sources. SEC.co and its analysts are not liable for decisions made based on this analysis; each organization must conduct its own risk assessment and testing before deploying patches in production environments. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-10984MEDIUMGoogle Chrome Android UI Spoofing Vulnerability – Medium Severity
- CVE-2026-11001MEDIUMGoogle Chrome UI Spoofing in Payments – Patch Now
- CVE-2026-11019MEDIUMChrome Android Payments Domain Spoofing Vulnerability
- CVE-2026-11107MEDIUMGoogle Chrome UI Spoofing Vulnerability – Patch Guide
- CVE-2026-11215MEDIUMChrome Android Domain Spoofing Vulnerability
- CVE-2026-11216MEDIUMChrome File Input UI Spoofing – Patch to 149.0.7827.53
- CVE-2026-11222MEDIUMChrome Tab Strip Domain Spoofing Vulnerability – Patch Guide
- CVE-2026-11225MEDIUMChrome Domain Spoofing Vulnerability – Patch Guidance