Impact
The vulnerability allows a remote attacker to present a crafted web page that renders UI elements which appear indistinguishable from the browser’s native interface. By exploiting this UI misrepresentation, an attacker can deceive users into performing actions such as submitting credentials or approving sensitive operations. The flaw is categorized as CWE-451 – UI Integrity, indicating that legitimate interface integrity cannot be guaranteed.
Affected Systems
Google Chrome versions before 155.0.8059.39 are vulnerable. The flaw exists on all platforms supported by Chrome’s stable channel. Users running any unsupported or earlier build are affected.
Risk and Exploitability
The exploit relies on a user visiting a maliciously crafted HTML page, a scenario typical of social engineering phishing attacks. With no EPSS score available and no listing in CISA KEV, the documented severity is Medium. The probability of exploitation is moderate, given that the attack requires user interaction but no additional network exposure or privileged access.
OpenCVE Enrichment