Impact
An incorrect reference resolution flaw in Google Chrome on macOS permits a remote attacker, using social engineering to luring a user to a specially crafted HTML page, to gain access to sensitive information that the browser would normally protect. The flaw is classified as Improper Access Control (CWE‑706).
Affected Systems
The vulnerability is present in all Google Chrome for macOS versions earlier than 155.0.8059.39. Versions 155.0.8059.40 and later contain the fix, so any machine running the outdated browser remains susceptible.
Risk and Exploitability
The issue carries a CVSS score of 8.8, indicating high severity. No EPSS data is available, and the vulnerability is not listed in the CISA KEV catalog. Because the attack requires only a malicious web page and a user’s interaction, the probability of exploitation depends largely on successful social engineering; once triggered, the attacker can expose private information to which the browser should have restricted access.
OpenCVE Enrichment