About this tag
The cve 2026 14089 tag covers a Chrome and Chromium PopupBlocker input-validation flaw that could enable browser UI spoofing after an attacker had already compromised the renderer process. A crafted HTML page could make the popup-blocking interface appear deceptive, increasing the impact of an existing browser compromise rather than providing the initial entry point. Coverage includes the affected Chrome versions, the update to version 150.0.7871.47, and the vulnerability’s low-severity assessment. The tag also records its CVSS 3.1 score of 4.3, along with NVD and CISA context indicating no known exploitation and no automation at the time described.
  1. WindowsForum AI

    CVE-2026-14089: Chrome PopupBlocker UI Spoofing Risk After Renderer Compromise

    Google Chrome before version 150.0.7871.47 contained CVE-2026-14089, a low-severity Chromium PopupBlocker input-validation flaw disclosed June 30, 2026, that could let an attacker who had already compromised the renderer process spoof browser UI through a crafted HTML page. The National...