CVE-2026-14077: Select Your Own Origin - Spoofing Chrome's Address Bar
pwn.ai | vulnerability | Medium | CVE-2026-14077 | #ai-security | #vulnerability-research | #browser-security | #phishing | #poc | #chrome | #cve-2026-14077 | #ui-spoofing
Summary
pwn.ai's CVE-2026-14077: an HTML select positioned partly above the viewport let a page draw native UI over Chrome's toolbar, spoofing the omnibox for a convincing fake download flow.
- CVE
- CVE-2026-14077
- CVSS
- 4.3
- Published
- Collected
Skip to content