Impact
The vulnerability is a missing authorization check in the Chromoting component of Google Chrome for Windows. A remote attacker who can send specially crafted network traffic can bypass the expected access controls and capture sensitive information that is normally protected during a Chromoting session. The flaw falls under CWE‑862 and is classified as a medium‑severity issue by Chromium security.
Affected Systems
This issue affects Google Chrome versions prior to 155.0.8059.39 on Windows operating systems. Users who run older builds of Chrome and have Chromoting enabled are potentially vulnerable. All other platforms and newer Chrome releases are not impacted.
Risk and Exploitability
The vulnerability can be exploited from the network if the attacker can reach the Chromoting service. No EPSS score is publicly available and the issue is not listed in the CISA KEV catalog, indicating no confirmed widespread exploitation at this time. Despite that, the ability to obtain private session data may provide an attacker with valuable credentials or content. Because the flaw is remotely exploitable without local privileges, the risk remains significant.
OpenCVE Enrichment