Impact
A web‑browser flaw in Google Chrome on macOS versions before 155.0.8059.39 allows a remote attacker to craft network traffic that causes the Chromoting UI to display forged elements. The attacker can present fake dialog boxes or icons that appear to be part of the browser, thereby enabling a social‑engineering attack such as phishing or credential theft. The Chromium security team assigned a low severity rating, but the attack vector is remote and requires only that the victim load the compromised URL or click a malicious link.
Affected Systems
All users running Google Chrome on macOS with a revision prior to 155.0.8059.39 are affected. The vulnerability is tied to the Chromoting component of the browser and does not affect other Google products.
Risk and Exploitability
The vulnerability has no publicly defined CVSS score or EPSS value, and it is not listed in the CISA KEV catalog, which suggests that widespread exploitation has not been documented. However, the flaw can be leveraged by sending specially crafted packets over a network that the victim uses, and because it relies on social engineering, successful exploitation depends on user interaction rather than automated hacking. The risk is moderate for users who frequently interact with untrusted web content, especially if Chromoting is enabled.
OpenCVE Enrichment