Impact
Clickjacking in the EVP (Event‑Vector Processing) component of Google Chrome prior to 155.0.8059.39 allows a web‑based attack to cause a user to interact with hidden or masqueraded user interface elements. An attacker can embed a maliciously crafted HTML page that causes the victim to click a button or link that performs an unintended action, or displays UI elements that do not match what is actually presented. The weakness is classified as CWE-1021. The Chromium security team rated the vulnerability as medium severity.
Affected Systems
All desktop installations of Google Chrome running a version older than 155.0.8059.39 are affected. Mobile or other non‑desktop Chrome environments that rely on a different code base are not listed as impacted by this entry.
Risk and Exploitability
The flaw can be leveraged by a remote attacker who hosts a malicious web page and tricks a user into visiting it. Because the exploit depends on user interaction, the risk of successful exploitation is bounded by the likelihood that a user will open a compromised site. The CVSS score of 5.4 indicates moderate severity. No EPSS score is presently available and the vulnerability is not listed in CISA’s KEV catalog, which suggests there is currently no widespread, publicly reported exploitation. Nevertheless, the lack of an EPSS score does not eliminate the possibility of exploitation, and why prompt patching is advised.
OpenCVE Enrichment