Description
UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: UI Spoofing enabling social engineering
Action: Assess Impact
AI Analysis

Impact

The vulnerability involves UI misrepresentation in Chromoting when Chrome runs on Windows, allowing a remote attacker to spoof UI elements through crafted network traffic. This can mislead users into interacting with counterfeit dialogs or controls, enabling social‑engineering attacks. The impact does not include code execution or data exfiltration; it primarily facilitates deception and potential credential compromise if users are tricked into providing sensitive information.

Affected Systems

Google Chrome running on Windows, versions older than 155.0.8059.39, are affected. No specific build numbers beyond the stated upper bound are listed.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting low exploitation likelihood at present. The CVE is scored low by Chromium’s severity model, and the attack would require an attacker to deliver crafted network traffic to a Chrome instance that has Chromoting enabled. Based on the description, the likely attack vector is remote, via the Chromium network stack, and the vulnerability hinges on insufficient validation of data received from a remote connection.

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Chrome 155.0.8059.39 or newer to receive the patched Chromoting code.
  • Disable Chromoting connections or restrict them to known, trusted servers via Chrome policies.
  • Educate users not to trust unexpected modal dialogs or prompts that appear to be part of Chrome’s UI; encourage reporting of suspicious UI changes.

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Chromoting in Chrome on Windows

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Chromoting in Google Chrome on on Windows prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-451
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:56.554Z

Reserved: 2026-10-06T16:32:51.892Z

Link: CVE-2026-106236

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:09.184Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:50.470

Modified: 2026-10-06T21:17:07.830

Link: CVE-2026-106236

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information