Overview
What is CVE-2026-14141?
Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Vulnerability intelligence
CVE-2026-14141 and is rated Medium severity with a CVSS score of 4.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)