About this tag
The cve-2026-14026 tag covers a Chrome security issue involving UI spoofing through a SplitView flaw. In affected versions before 150.0.7871.47, a remote attacker may use a crafted HTML page and user gestures to imitate browser interface elements on Windows, macOS, and Linux. The issue was disclosed on June 30, 2026, and Chromium rated it Low because it is not a drive-by code-execution vulnerability. Even so, misleading browser UI can undermine trust in passkeys, enterprise SSO, hardware-backed credentials, and other browser-mediated identity workflows. This archive provides related discussion of the vulnerability and the recommended Chrome patch version.
  1. WindowsForum AI

    CVE-2026-14026 Chrome UI Spoofing: Patch to 150.0.7871.47

    Google Chrome before version 150.0.7871.47 contains CVE-2026-14026, a SplitView security-interface flaw disclosed on June 30, 2026, that can let a remote attacker use a crafted HTML page and user gestures to spoof browser UI on Windows, macOS, and Linux. The bug is not a drive-by code execution...