Impact
A flaw in the Paint module of Google Chrome allows an attacker to deliver a crafted web page that misrepresents user interface elements. The vulnerability can cause the browser to display harmless‑looking elements that actually invoke malicious actions, potentially tricking users into interacting with or accepting harmful content. The weakness is a UI misrepresentation flaw (CWE‑451) and does not provide direct code execution but enables deceptive presentation.
Affected Systems
The issue affects Google Chrome on all platforms running a version earlier than 155.0.8059.39. Users with these legacy builds are susceptible until the patch is applied.
Risk and Exploitability
The attack vector is remote; a malicious site can host an HTML page that exploits the Paint UI misrepresentation. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Though its CVSS score of 5.4 indicates Medium severity, the lack of a known exploit and the reliance on user interaction mean the risk is moderate but still relevant, especially for users who may not recognize spoofed UI elements.
OpenCVE Enrichment