CVE-2026-14127: Chrome Printing UI Spoofing Vulnerability (v150.0.7871.47)
Google Chrome versions prior to 150.0.7871.47 contain a flaw in how the browser handles printing functionality that could allow an attacker to trick users into believing they are interacting with legitimate content when they are not. The vulnerability requires the attacker to have first compromised the Chrome renderer process—the sandboxed component responsible for displaying web content—and then use a specially crafted webpage to create a fake or misleading user interface. While the underlying issue is classified as low severity by the Chromium project, the CVSS scoring reflects the user interaction required and the limited scope of potential impact.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.3 MEDIUM · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-20, CWE-451
- Affected products
- 1 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-02
NVD description (verbatim)
Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
The vulnerability stems from inappropriate implementation logic in Chrome's printing subsystem prior to version 150.0.7871.47. The flaw resides in CWE-20 (Improper Input Validation) and CWE-451 (User Interface (UI) Misrepresentation of Critical Information), allowing a compromised renderer process to manipulate print-related UI elements via crafted HTML. The attack vector is network-based with low attack complexity, but requires prior compromise of the renderer sandbox—a significant prerequisite that limits real-world exposure. The integrity impact is limited to UI spoofing; no confidentiality or availability compromise occurs.
Business impact
The practical business risk is moderate. An attacker would need to have already compromised the renderer process through another vulnerability or attack chain, making this a secondary threat rather than an entry point. The damage is limited to user deception regarding print dialogs or related UI elements, which could lead to users unknowingly printing sensitive information, revealing browsing context, or being misdirected. For organizations managing Chrome deployments at scale, the primary concern is ensuring timely patching to prevent multi-stage attacks where this flaw is chained with other exploits.
Affected systems
Google Chrome versions prior to 150.0.7871.47 are affected. This includes all Chrome releases, across all platforms (Windows, macOS, Linux, Android, iOS), shipped before the patched version. Users running Chrome on any operating system with a version number below 150.0.7871.47 are potentially vulnerable. Organizations should verify their deployed Chrome version against this threshold.
Exploitability
Exploitation requires two conditions: (1) the attacker must first compromise the Chrome renderer process through a separate vulnerability, and (2) the user must visit a page containing the crafted HTML payload. The renderer sandbox is designed to prevent arbitrary code execution from web content, so a prior compromise is a significant barrier. Once the renderer is compromised, the UI spoofing itself is reliable, but the initial compromise step makes practical exploitation less likely than single-stage vulnerabilities. No public exploit code is known to exist.
Remediation
Update Google Chrome to version 150.0.7871.47 or later. Chrome's auto-update mechanism typically deploys patches within days of release. Organizations can force immediate updates via policy in Chrome Enterprise environments. No workarounds exist for the vulnerability itself, though restricting access to untrusted websites reduces the attack surface by limiting renderer compromise attempts.
Patch guidance
Verify your Chrome version by navigating to chrome://settings/help, which will display the installed version and initiate any pending updates automatically. For Chrome Enterprise deployments, administrators can enforce updates through the PoliciesForLinux, macOS, or Windows (depending on your platform) using the 'Update policies' configuration. Version 150.0.7871.47 or later resolves the issue. Test the patch in a non-production environment if your organization has critical Chrome-dependent workflows.
Detection guidance
Monitor for indicators of renderer process compromise, which is the prerequisite for this attack. Endpoint detection and response (EDR) tools should flag unusual Chrome renderer process behavior, memory access patterns, or spawning of unexpected child processes. Browser logs and crash reports (if enabled in your environment) may show abnormal terminations or security interventions. Since the vulnerability requires prior compromise, focus detection efforts on the initial renderer exploitation vector rather than the UI spoofing itself, which leaves minimal forensic traces.
Why prioritize this
This vulnerability merits timely but not emergency remediation. While the CVSS score of 4.3 (MEDIUM) reflects user interaction and limited impact, the requirement for prior renderer compromise significantly reduces the practical attack surface compared to direct renderer exploits. It is not on the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating no active in-the-wild exploitation has been reported. Prioritize patching within your standard update cycle (typically within 2–4 weeks), especially for endpoints handling sensitive information or facing elevated phishing risk.
Risk score, explained
The CVSS 3.1 score of 4.3 (MEDIUM) is driven by: Network-based attack vector (AV:N) indicating remote exploitation, low attack complexity (AC:L) once renderer is compromised, no privileges required (PR:N) to trigger the spoofing, required user interaction (UI:R) to visit the malicious page, and limited integrity impact (I:L) affecting only UI representation. The score appropriately penalizes the vulnerability for requiring prior renderer process compromise (implicitly captured in the complexity of the overall attack chain) and the non-critical nature of the impact. The absence of confidentiality or availability impact keeps the severity below HIGH.
Frequently asked questions
Can this vulnerability be exploited directly by visiting a malicious website?
No. The vulnerability requires the renderer process to be compromised first through a separate vulnerability. Once compromised, the attacker can then use a crafted HTML page to perform UI spoofing. Direct exploitation through a single webpage is not possible.
What does 'UI spoofing' mean in this context, and why is it a security concern?
UI spoofing means creating a fake or misleading user interface to deceive the user. In this case, the attacker could manipulate print-related dialogs or other UI elements to trick users into unwanted actions, such as printing sensitive data or believing they are interacting with legitimate browser controls when they are not.
Why is this vulnerability not listed in CISA's Known Exploited Vulnerabilities catalog?
The KEV catalog includes only vulnerabilities being actively exploited in the wild. This vulnerability has not been observed in active exploitation campaigns. However, the absence from the KEV list does not mean the vulnerability is unimportant—it should still be patched as part of your regular Chrome update schedule.
Do I need to disable Chrome or use a different browser until I patch this?
Disabling Chrome is not necessary. The vulnerability is not easily exploitable in real-world conditions and requires prior compromise of the renderer. Continue using Chrome while implementing your normal update processes. If you manage Chrome across an organization, prioritize patching systems over the next 2–4 weeks according to your standard deployment procedures.
This analysis is provided for informational purposes and represents the current state of publicly available information regarding CVE-2026-14127 as of the publication date. Verify all patch versions, affected product details, and remediation steps against the official Google Chrome security advisory and your organization's systems. CVSS scores and severity ratings are sourced from the official CVE record and Chromium security team assessments. This explainer does not constitute legal advice, warranty, or guarantee of security. Organizations are responsible for assessing their own risk tolerance and deploying updates according to their change management and security policies. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-11286MEDIUMChrome Wallet UI Spoofing Vulnerability – Patch Guidance
- CVE-2026-14130MEDIUMChrome Omnibox UI Spoofing Vulnerability – Patch Guide
- CVE-2026-0018MEDIUMAndroid AccessibilityManagerService Denial of Service Vulnerability
- CVE-2026-0051MEDIUMAndroid UBSan Runtime Denial of Service Vulnerability
- CVE-2026-0070MEDIUMAndroid DevicePolicyManagerService Local Denial of Service Vulnerability
- CVE-2026-0085MEDIUMAndroid Contact Handler Denial of Service Vulnerability
- CVE-2026-10004MEDIUMChrome UI Spoofing Vulnerability – Password Dialog Hijacking
- CVE-2026-10912MEDIUMChrome Extension Same-Origin Policy Bypass (CVSS 6.5)