Impact
Improper input validation in the SignIn component of Google Chrome allowed a remote attacker to craft a malicious Chrome extension and use social engineering to trick users into installing it, thereby bypassing system access restrictions and potentially gaining unauthorized privileges.
Affected Systems
Google Chrome versions earlier than 155.0.8059.39 are affected.
Risk and Exploitability
The vulnerability is a medium‑severity flaw with no EPSS value available and is not listed in the CISA KEV catalog. Attackers would need to execute a social‑engineering scheme to get users to install a malicious extension. The lack of an EPSS score indicates that current exploitation data is unknown, but the medium overall severity suggests a realistic risk if the user is susceptible to the social‑engineering tactic.
OpenCVE Enrichment