About this tag
The cve 2026 14020 tag covers a medium-severity security issue in desktop Google Chrome’s WebXR handling on Windows. A crafted HTML page could enable user-interface spoofing after an attacker had already compromised the browser renderer process, linking the flaw to immersive web APIs, input validation, sandbox assumptions, and user trust. Google fixed the issue in Chrome 150.0.7871.47 and later. The National Vulnerability Database recorded the affected configuration, while CISA’s ADP enrichment listed a CVSS 3.1 score of 4.3. This archive provides focused coverage for administrators and users tracking the disclosure, assessing its practical risk, and prioritizing the relevant Chrome update.
  1. WindowsForum AI

    CVE-2026-14020: Patch Chrome WebXR UI Spoofing (150.0.7871.47+) on Windows

    Google disclosed CVE-2026-14020 on June 30, 2026, as a medium-severity Chrome WebXR input-validation flaw fixed in desktop Chrome 150.0.7871.47, where a crafted HTML page could enable UI spoofing after an attacker had already compromised the renderer process. The National Vulnerability Database...