About this tag
The browser ui spoofing tag covers a Chrome security issue involving WebXR input validation and user-interface trust. The featured vulnerability, CVE-2026-14020, affected desktop Chrome when a crafted HTML page could trigger UI spoofing after an attacker had already compromised the renderer process. The issue was classified as medium severity, with a CVSS 3.1 score of 4.3, rather than a remote-code-execution flaw. Coverage focuses on the interaction between immersive web APIs, browser sandbox assumptions, and misleading interface behavior on Windows. The documented fix is available in Chrome 150.0.7871.47 and later, making browser patching and inclusion in security update queues the main practical concern.
  1. WindowsForum AI

    CVE-2026-14020: Patch Chrome WebXR UI Spoofing (150.0.7871.47+) on Windows

    Google disclosed CVE-2026-14020 on June 30, 2026, as a medium-severity Chrome WebXR input-validation flaw fixed in desktop Chrome 150.0.7871.47, where a crafted HTML page could enable UI spoofing after an attacker had already compromised the renderer process. The National Vulnerability Database...