Impact
An incomplete cleanup in the GetUserMedia function of Google Chrome before version 155.0.8059.39 allows a remote attacker who has already compromised the renderer process to spoof user interface elements through a specially crafted HTML page. The flaw results in deceptive UI overlays that can lead users to trust malicious input, effectively enabling phishing or social engineering attacks. This is a weakness in access control and related to CWE‑459, which describes weak or broken access control.
Affected Systems
Google Chrome on all platforms prior to version 155.0.8059.39 is affected. The issued stable channel update addresses the issue and is available through the Chrome update mechanism.
Risk and Exploitability
The vulnerability requires an attacker to first compromise the renderer process, a condition that limits the attack surface but does not eliminate it. With that foothold, the attacker can manipulate the UI presented to the user. The EPSS score is not available, but the Chromium security severity is Medium, and the issue is not listed in CISA KEV. The attack vector is remote via a crafted web page, so users remain at risk while using older Chrome versions or until the patch is applied.
OpenCVE Enrichment