Impact
The vulnerability involves UI misrepresentation in Chromoting when Chrome runs on Windows, allowing a remote attacker to spoof UI elements through crafted network traffic. This can mislead users into interacting with counterfeit dialogs or controls, enabling social‑engineering attacks. The impact does not include code execution or data exfiltration; it primarily facilitates deception and potential credential compromise if users are tricked into providing sensitive information.
Affected Systems
Google Chrome running on Windows, versions older than 155.0.8059.39, are affected. No specific build numbers beyond the stated upper bound are listed.
Risk and Exploitability
The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting low exploitation likelihood at present. The CVE is scored low by Chromium’s severity model, and the attack would require an attacker to deliver crafted network traffic to a Chrome instance that has Chromoting enabled. Based on the description, the likely attack vector is remote, via the Chromium network stack, and the vulnerability hinges on insufficient validation of data received from a remote connection.
OpenCVE Enrichment