CVE-2026-14110: Chrome Dark Mode UI Spoofing Vulnerability
Google Chrome versions before 150.0.7871.47 contain a vulnerability in the Dark Mode feature that allows an attacker to deceive users through crafted web pages. By manipulating how Dark Mode renders interface elements, an attacker could trick users into believing they are interacting with legitimate browser controls or content when they are not. This is a client-side UI spoofing vulnerability that requires user interaction to exploit.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-1021, CWE-451
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-02
NVD description (verbatim)
Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-14110 stems from improper implementation in Chrome's Dark Mode rendering logic. The vulnerability enables a remote, unauthenticated attacker to craft malicious HTML that exploits how Dark Mode processes or displays UI elements, resulting in visual deception. The issue is classified as CWE-1021 (Improper Restriction of Rendered UI Layers or Frames) and CWE-451 (User Interface (UI) Misrepresentation of Critical Information), indicating the attacker can manipulate what users see on screen. Chromium's security team rated the underlying issue as Low severity, though the CVSS 3.1 score of 4.3 reflects the need for user interaction and the integrity-only impact profile.
Business impact
This vulnerability poses a moderate social engineering risk. While it cannot directly steal data or execute commands, successful exploitation could facilitate phishing attacks, credential harvesting, or malware distribution by making malicious interfaces appear legitimate. Users might unknowingly grant permissions, enter sensitive information, or click malicious links if the spoofed UI is convincing. Organizations relying on Chrome for secure internal workflows should weigh this against their threat model—particularly if users are frequently targets of phishing campaigns.
Affected systems
The vulnerability affects Google Chrome versions prior to 150.0.7871.47. All platforms running affected Chrome versions—Windows, macOS, and Linux—are potentially impacted. Any user browsing untrusted websites while using a vulnerable Chrome build is at risk. Chrome OS devices running vulnerable versions are also in scope. Mobile Chrome (if it uses the same Dark Mode rendering path) may be affected depending on version alignment.
Exploitability
Exploitation requires low technical effort and no special privileges. An attacker simply needs to host or inject a crafted HTML page into the victim's browser session. The CVSS vector (AV:N/AC:L/PR:N/UI:R/S:U) confirms that the attack is network-accessible, has low attack complexity, requires no authentication, and depends on user interaction—specifically the user visiting or viewing the malicious page. The attack does not appear in CISA's Known Exploited Vulnerabilities (KEV) catalog, suggesting no active exploitation has been publicly disclosed or tracked as of the publication date.
Remediation
Update Google Chrome to version 150.0.7871.47 or later. This patch corrects the Dark Mode rendering logic to prevent UI spoofing. Organizations should prioritize this update for end-user devices, particularly those used for high-risk activities such as financial transactions or access to sensitive applications. Enable Chrome's auto-update mechanism where possible to reduce manual patching overhead.
Patch guidance
Chrome typically auto-updates on restart. Users can manually verify their version by navigating to Chrome menu > About Google Chrome, which will trigger an immediate check for updates if available. Enterprise deployments should verify that version 150.0.7871.47 or later is rolled out across their estate using Chrome's enterprise policy management tools or endpoint management solutions. Test the patch in a non-production environment first to rule out compatibility issues, though this is a security patch and rollback is not recommended.
Detection guidance
Monitor Chrome version inventory using endpoint detection and response (EDR) tools or software asset management (SAM) solutions to identify systems still running versions prior to 150.0.7871.47. Browser telemetry and update reporting dashboards can help track adoption of the patched version. Network detection is limited since the attack occurs client-side; focus on behavioral indicators such as users reporting unexpected UI behavior or permission prompts. If available, enable Chrome security event logging and review for suspicious Dark Mode or rendering anomalies.
Why prioritize this
Although the CVSS score is 4.3 (MEDIUM) and Chromium rated it Low severity, the low barrier to exploitation, absence of authentication, and potential for social engineering warrant timely patching. This is not a critical emergency, but it should not be deferred indefinitely—treat it as a standard security update cycle. The lack of known active exploitation means this is a good opportunity to patch proactively before threat actors weaponize the technique.
Risk score, explained
The CVSS 3.1 score of 4.3 reflects: (1) network-accessible attack vector with no authentication required, reducing the attack surface friction; (2) low attack complexity, meaning the exploit is straightforward to develop; (3) user interaction requirement, which limits the attack scope; (4) integrity impact only (users can be deceived), with no confidentiality or availability loss; and (5) unchanged scope, confirming the attack does not cross privilege boundaries. The MEDIUM severity designation balances the ease of exploitation against the limited direct technical impact.
Frequently asked questions
Can this vulnerability steal my passwords or data directly?
No. CVE-2026-14110 is a UI spoofing flaw that tricks users into believing they are interacting with something legitimate. The vulnerability itself does not exfiltrate data. However, if an attacker successfully spoofs a login form or permission dialog, users might voluntarily enter credentials or grant permissions, leading to a secondary compromise.
Do I need to update if I use Chrome in Dark Mode?
Yes. The vulnerability exists in Chrome's Dark Mode rendering code, so it primarily affects users with Dark Mode enabled. However, updating is still recommended for all users as a general security practice, and because it takes minimal effort.
Is this vulnerability being actively exploited?
As of the publication date (June 30, 2026), CVE-2026-14110 is not listed in CISA's Known Exploited Vulnerabilities catalog, indicating no widespread active exploitation has been publicly documented. However, this does not guarantee future activity; organizations should still patch within their normal update cycle.
What should I do if I suspect I was tricked by a spoofed UI?
If you believe you interacted with a fraudulent interface and entered sensitive information, change your passwords immediately, enable multi-factor authentication if available, and monitor accounts for unauthorized activity. Report the incident to your security team and provide them with the URL or details of the suspicious page.
This analysis is based on official CVE records, Chromium security advisories, and CVSS 3.1 scoring guidelines as of the publication date. Patch version numbers and affected product details are derived from the authoritative vendor advisory; verify current availability and applicability to your environment. This assessment does not constitute legal or compliance advice. Organizations should consult their risk management frameworks and security policies when prioritizing patch deployment. SEC.co makes no warranty regarding the completeness or timeliness of this intelligence and recommends continuous monitoring of official vendor channels for the latest updates. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-14142MEDIUMGoogle Chrome Extension UI Spoofing Vulnerability
- CVE-2026-0061MEDIUMAndroid WindowState Tapjacking Vulnerability – Permission Escalation Risk
- CVE-2026-10984MEDIUMGoogle Chrome Android UI Spoofing Vulnerability – Medium Severity
- CVE-2026-11001MEDIUMGoogle Chrome UI Spoofing in Payments – Patch Now
- CVE-2026-11019MEDIUMChrome Android Payments Domain Spoofing Vulnerability
- CVE-2026-11107MEDIUMGoogle Chrome UI Spoofing Vulnerability – Patch Guide
- CVE-2026-11215MEDIUMChrome Android Domain Spoofing Vulnerability
- CVE-2026-11216MEDIUMChrome File Input UI Spoofing – Patch to 149.0.7827.53