Description
UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: UI Spoofing via Crafted Network Traffic
Action: Patch
AI Analysis

Impact

A web‑browser flaw in Google Chrome on macOS versions before 155.0.8059.39 allows a remote attacker to craft network traffic that causes the Chromoting UI to display forged elements. The attacker can present fake dialog boxes or icons that appear to be part of the browser, thereby enabling a social‑engineering attack such as phishing or credential theft. The Chromium security team assigned a low severity rating, but the attack vector is remote and requires only that the victim load the compromised URL or click a malicious link.

Affected Systems

All users running Google Chrome on macOS with a revision prior to 155.0.8059.39 are affected. The vulnerability is tied to the Chromoting component of the browser and does not affect other Google products.

Risk and Exploitability

The vulnerability has no publicly defined CVSS score or EPSS value, and it is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not been documented. However, the flaw can be leveraged by sending specially crafted packets over a network that the victim uses, and because it relies on social engineering, successful exploitation depends on user interaction rather than automated hacking. The risk is moderate for users who frequently interact with untrusted web content, especially if Chromoting is enabled.

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later
  • Disable the Chromoting feature via Chrome policies if it is not required for user workflows
  • Educate users to be wary of unexpected UI prompts and to verify the source of displayed information

Generated by OpenCVE AI on October 6, 2026 at 21:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 21:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Network Traffic in Chrome on macOS

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Chromoting in Google Chrome on on Mac prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via crafted network traffic. (Chromium security severity: Low)
Weaknesses CWE-451
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:56.430Z

Reserved: 2026-10-06T16:33:31.400Z

Link: CVE-2026-106251

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:07.325Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:52.173

Modified: 2026-10-06T21:17:08.713

Link: CVE-2026-106251

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T21:30:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information