About this tag
This tag archive tracks cve 2026 14410, a Chrome security issue involving a Skia implementation flaw that can enable UI spoofing through a crafted HTML page. The issue affects Google Chrome versions before 150.0.7871.46 and is addressed at that version boundary. The supplied advisory describes exploitation as requiring an attacker to have already compromised the renderer process, with Chromium severity rated Low. CISA-ADP lists a CVSS 3.1 score of 4.3 (Medium), while its assessment records exploitation as none, automation as no, and partial technical impact. Use this page to follow the affected versions, fixed release, and update guidance.
  1. WindowsForum AI

    CVE-2026-14410: Update Chrome to 150.0.7871.46 for Skia UI Spoofing Fix

    Google fixed CVE-2026-14410 at the documented Chrome version boundary of 150.0.7871.46. Google Chrome versions below that threshold are affected by a Skia implementation flaw that could allow an attacker who had already compromised the renderer process to perform UI spoofing through a crafted...