Impact
A crafted HTML page can manipulate the Chrome file dialog’s visual elements so that a malicious website can present fake prompts or buttons to the user. By misrepresenting the UI, an attacker can trick users into believing they are interacting with legitimate system interfaces, potentially causing them to grant credentials, confirm downloads, or execute unintended actions. The vulnerability does not by itself allow arbitrary code execution; it merely exploits human trust in the browser’s UI.
Affected Systems
Google Chrome browsers older than version 155.0.8059.39 are affected, including all releases before this patch. The flaw is present in the file dialog rendering logic of the Chrome UI component and can be triggered from any webpage that the user visits in these versions.
Risk and Exploitability
The flaw is exploitable without the need for local code execution, relying on a socially engineered user interacting with a malicious webpage. No exploit probability metric is available, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.4 indicates medium severity. Because the attacker must host a crafted page and lure a user to open it, the likelihood of widespread exploitation is limited, but the potential for targeted phishing remains significant.
OpenCVE Enrichment