CVE-2026-14154: Chrome DevTools UI Spoofing Vulnerability in Extensions
CVE-2026-14154 is a UI spoofing vulnerability in Google Chrome's DevTools that requires an attacker to trick a user into installing a malicious extension. Once installed, the extension can display fake interface elements to deceive users, potentially leading to credential theft or social engineering attacks. While Google rates this as low severity, the attack chain depends on user action to install the extension, which limits but does not eliminate risk.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 4.8 MEDIUM · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
- Weaknesses (CWE)
- CWE-451
- Affected products
- 4 configuration(s)
- Published / Modified
- 2026-06-30 / 2026-07-01
NVD description (verbatim)
Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (Chromium security severity: Low)
2 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
This vulnerability stems from an inappropriate implementation in Chrome's DevTools component affecting versions prior to 150.0.7871.47. The flaw allows a crafted malicious extension to perform UI spoofing—creating counterfeit browser interface elements or overlays. The attack vector is network-based with high complexity (AC:H), as it requires convincing a user to install the extension. The vulnerability results in limited integrity and availability impact (I:L/A:L) rather than confidentiality breaches. It maps to CWE-451 (User Interface Inconsistency), which encompasses improper display of security-relevant information.
Business impact
UI spoofing via malicious extensions poses a credential harvesting and social engineering risk. An attacker could overlay fake login prompts, payment forms, or warning dialogs on top of legitimate browser content. This is particularly concerning for organizations where end users visit sensitive sites (banking, email, corporate SSO portals) without realizing they're interacting with spoofed interfaces. While the CVSS score is moderate (4.8), the real-world impact depends on user awareness and the sophistication of the spoofed interface.
Affected systems
Google Chrome versions before 150.0.7871.47 are vulnerable on Windows, macOS, and Linux systems. The vulnerability does not affect the underlying operating system kernels but rather the Chrome browser application itself across all supported platforms.
Exploitability
Exploitation requires social engineering to convince a user to install a malicious Chrome extension from outside the official Web Store, or via compromise of a developer account hosting an extension. The attack complexity is high due to this user interaction requirement, and there is no evidence of widespread weaponization or public exploit code. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog.
Remediation
Users and administrators should update Google Chrome to version 150.0.7871.47 or later as soon as possible. Additionally, enforce extension management policies to restrict installation from untrusted sources, disable developer mode for non-technical users, and consider using enterprise policies to block specific extensions or limit extension permissions. Educate end users on the risks of installing extensions from unknown sources.
Patch guidance
Google Chrome auto-updates on most platforms, but verify that devices have updated to 150.0.7871.47 or later. For managed deployments, use Chrome Enterprise policies to enforce updates and restrict extension installation. Test the patch in a non-production environment before wide deployment if you use custom extensions that interact with DevTools. No rollback or workaround is necessary once patched.
Detection guidance
Monitor for suspicious extension installations on endpoints using endpoint detection and response (EDR) tools or Chrome policy reporting. Look for extensions with unusual permissions, particularly those requesting access to DevTools APIs or ability to inject scripts into web pages. Enable Chrome's extension reporting features in your organization's admin console. While the vulnerability itself is difficult to detect once triggered, detecting the malicious extension installation is the primary control.
Why prioritize this
This vulnerability warrants a medium priority status despite its low Chromium severity rating because it targets a common attack vector (browser extensions) and can lead to credential compromise. Organizations with high-risk users accessing sensitive web applications should prioritize patching first. However, it is not critical because exploitation requires substantial user interaction (installing an extension), and there is no evidence of active exploitation in the wild.
Risk score, explained
The CVSS 3.1 score of 4.8 (MEDIUM) reflects the moderate but real impact of UI spoofing (integrity and availability degradation) combined with the high barrier to exploitation (user must install extension, network vector but not directly weaponizable). The score appropriately discounts confidentiality impact since spoofing does not directly exfiltrate data. Organizations handling sensitive transactions should weight their risk assessment slightly higher due to social engineering potential.
Frequently asked questions
Can this vulnerability be exploited without user interaction?
No. The attacker must convince the user to install a malicious extension. There is no attack vector that exploits the vulnerability remotely without any user action.
Does this affect Chrome extensions I install from the Chrome Web Store?
The Chrome Web Store has security reviews and policies that make it unlikely (though not impossible) for spoofing-capable malicious extensions to be published. The highest risk is from side-loaded extensions or those installed from third-party sources.
What does 'UI spoofing' actually allow an attacker to do?
UI spoofing allows an attacker to display fake browser dialogs, overlays, or interface elements that appear legitimate. Common attacks include fake login prompts, fake payment forms, or fake security warnings designed to trick users into entering credentials or sensitive information.
If I have Chrome automatic updates enabled, am I protected?
Automatic updates typically deploy within days of release on most systems. However, you should verify your Chrome version (chrome://version) to confirm you are running 150.0.7871.47 or later. Enterprises may have update policies that delay deployment.
This analysis is based on the CVE record and publicly available vulnerability data current as of the publication date. Severity and exploitability may vary depending on organizational context and user behavior. Verify patch version numbers and availability directly with Google Chrome release notes and your vendor advisories. SEC.co does not provide legal or compliance advice; consult your security and legal teams regarding remediation timelines for your specific environment. No exploit code or weaponized proof-of-concept is provided or endorsed. Source: NVD (public-domain), retrieved 2026-08-09. Analysis generated by SEC.co (claude-haiku-4-5).
Weaknesses (CWE)
Related vulnerabilities
- CVE-2026-11107MEDIUMGoogle Chrome UI Spoofing Vulnerability – Patch Guide
- CVE-2026-11216MEDIUMChrome File Input UI Spoofing – Patch to 149.0.7827.53
- CVE-2026-11222MEDIUMChrome Tab Strip Domain Spoofing Vulnerability – Patch Guide
- CVE-2026-11225MEDIUMChrome Domain Spoofing Vulnerability – Patch Guidance
- CVE-2026-11227MEDIUMChrome Tab Hover Card Domain Spoofing Vulnerability
- CVE-2026-11228MEDIUMChrome UI Spoofing Vulnerability via File Input Flaw
- CVE-2026-11232MEDIUMGoogle Chrome TabGroups UI Spoofing Vulnerability
- CVE-2026-11245MEDIUMChrome UI Spoofing in Payments Component (CVSS 4.3)