Impact
Google Chrome versions prior to 155.0.8059.39 suffered a UI misrepresentation flaw in the WebOTP feature. A remote attacker could serve a crafted HTML page that tricks the browser into displaying spoofed user interface elements, potentially leading users to inadvertently provide sensitive information. The weakness is classified as CWE-451, indicating that information is revealed through incorrect UI or data presentation. The impact is primarily the potential for social‑engineering attacks where a victim is misled into interacting with malicious content. No elevated privileges are required beyond normal user interaction with the vulnerable browser page.
Affected Systems
The affected product is Google Chrome. Versions earlier than 155.0.8059.39 on all platforms are vulnerable, including the stable channel of the desktop client. No other Google products are listed as impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4 and is considered medium severity in Chromium’s internal scoring. EPSS is not available and the flaw is not listed in CISA’s KEV catalog. The attack vector is remote, but requires a victim to open a malicious page that triggers WebOTP. Because the flaw is an UI spoofing issue rather than a code‑execution or privilege‑escalation flaw, the likelihood of widespread exploitation is lower, yet the consequence is serious in an environment where users rely on OTP prompts.
OpenCVE Enrichment