Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-14134

CVE-2026-14134: Google Chrome Android XSS Vulnerability

CVE-2026-14134 is a UI spoofing XSS flaw in Google Chrome on Android that allows attackers to exploit Autofill via malicious HTML pages. This post explains its technical details, affected versions, impact, and mitigation.

Published:

CVE-2026-14134 Overview

CVE-2026-14134 is a user interface spoofing vulnerability in the Autofill component of Google Chrome on Android. Versions prior to 150.0.7871.47 contain an inappropriate implementation that allows a remote attacker to spoof UI elements via a crafted HTML page. The flaw is categorized under [CWE-451] (User Interface Misrepresentation of Critical Information). Exploitation requires user interaction, and the Chromium project rates the security severity as Low. The issue affects only the Android build of Chrome and does not impact confidentiality or availability.

Critical Impact

A remote attacker can render deceptive Autofill UI on a crafted web page to trick Android users into disclosing form data they believe is protected by browser-native controls.

Affected Products

  • Google Chrome on Android prior to 150.0.7871.47
  • Chromium-based Autofill implementation on Android
  • Downstream Chromium mobile browsers inheriting the pre-patch Autofill code

Discovery Timeline

  • 2026-06-30 - CVE-2026-14134 published to the National Vulnerability Database
  • 2026-07-01 - Last updated in NVD database

Technical Details for CVE-2026-14134

Vulnerability Analysis

The vulnerability resides in the Autofill subsystem of Chrome for Android. Autofill is responsible for surfacing saved credentials, addresses, and payment data through browser-controlled UI overlays. An inappropriate implementation permits a crafted HTML page to influence how or where Autofill UI is rendered relative to attacker-controlled page content.

Because the browser chrome and page content share visual space on mobile viewports, attackers can position page elements so they appear to belong to trusted Autofill prompts. Users interacting with what looks like a legitimate suggestion may instead interact with attacker-supplied content. The result is deceptive presentation of information the user assumes is authoritative.

The defect maps to [CWE-451], where security-relevant UI does not accurately represent the underlying state. The attack requires the victim to load the crafted page and interact with the spoofed prompt.

Root Cause

The root cause is inadequate isolation and positioning logic between Autofill UI surfaces and attacker-controlled page content on Android. The Autofill implementation fails to guarantee that its prompts cannot be visually mimicked or obscured by adjacent page-rendered elements. See the Chromium Issue Tracker Entry for maintainer discussion.

Attack Vector

The attack vector is network-based. An attacker hosts a malicious page and lures an Android Chrome user to visit it, typically through phishing links, malvertising, or compromised sites. The page uses crafted HTML and CSS to construct visuals that overlap or imitate Autofill UI. When the user taps a spoofed element, the attacker captures the interaction or induces disclosure of form data. No privileges are required, but user interaction is mandatory.

No verified proof-of-concept code has been published. Technical details are described in the Google Chrome Update Announcement.

Detection Methods for CVE-2026-14134

Indicators of Compromise

  • Android Chrome browser versions reporting a user agent string below 150.0.7871.47 in web server or proxy logs
  • Outbound requests from mobile endpoints to pages hosting overlay-heavy Autofill mimicry patterns, often correlated with phishing kits
  • User reports of unexpected credential or payment prompts on unrelated web pages

Detection Strategies

  • Inspect HTTP telemetry for Android Chrome user agents advertising versions prior to 150.0.7871.47 and flag them as unpatched
  • Correlate mobile browsing telemetry with threat intelligence feeds identifying phishing domains that abuse Autofill spoofing techniques
  • Review Mobile Threat Defense (MTD) alerts for suspicious page renderings and credential entry events on managed Android devices

Monitoring Recommendations

  • Track Chrome for Android version distribution across the managed device fleet through MDM inventory reports
  • Monitor DNS and web proxy logs for newly registered domains serving crafted HTML consistent with Autofill spoofing lures
  • Alert on repeated user-reported credential entry anomalies that map to unpatched Chrome versions on Android

How to Mitigate CVE-2026-14134

Immediate Actions Required

  • Update Google Chrome on all Android devices to version 150.0.7871.47 or later through the Google Play Store
  • Enforce automatic Play Store updates for Chrome through Android Enterprise or MDM policies
  • Communicate the risk of UI spoofing to end users and instruct them to verify Autofill prompts before submitting sensitive data

Patch Information

Google addressed the flaw in Chrome for Android 150.0.7871.47. Details are available in the Google Chrome Update Announcement and the corresponding Chromium Issue Tracker Entry. Organizations should confirm rollout completion through device management telemetry.

Workarounds

  • Disable Chrome Autofill for addresses, payment methods, and passwords on Android until the update is deployed
  • Use an enterprise password manager with dedicated autofill accessibility service in place of browser-native Autofill
  • Restrict access to untrusted websites on managed Android devices through DNS filtering or secure web gateway policies

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.