Inappropriate Implementation in Select in Google Chrome for Mac
CVE-2026-14077

4.3MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
30 June 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 3,040

What is CVE-2026-14077?

CVE-2026-14077 is a low-severity vulnerability found in Google Chrome for Mac, specifically affecting versions prior to 150.0.7871.47. It involves an inappropriate implementation within the browser's Select feature, which could allow a remote attacker to manipulate the content displayed in the Omnibox (URL bar). This manipulation could potentially mislead users into believing they are engaging with legitimate web content, thereby facilitating phishing attacks or other forms of cyber deception. The implications of this vulnerability are concerning for organizations as it undermines trust in the browser interface, which is critical for secure web browsing and online transactions.

Potential impact of CVE-2026-14077

  1. Phishing Risks: By exploiting this vulnerability, attackers could spoof URLs, making it appear as though the user is on a legitimate site when they are actually on a malicious page. This can lead to unauthorized access to sensitive information, including login credentials and financial data.

  2. User Trust Erosion: The ability for attackers to manipulate what users see in the URL bar can decrease trust in web browsing overall. Users may become more hesitant to share personal information online, affecting businesses that rely on e-commerce and online services.

  3. Security Awareness Challenges: Organizations may face increased challenges in educating employees about secure browsing practices if vulnerabilities like CVE-2026-14077 exist. This could lead to a greater likelihood of falling victim to social engineering attacks, ultimately compromising organizational security.

Affected Version(s)

Chrome 150.0.7871.47

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.