Impact
The vulnerability originates from an incorrect calculation in a Chrome API on Windows prior to version 155.0.8059.39, allowing a remote attacker to craft a malicious extension that can spoof user interface elements. This spoofing can mislead users into believing they are interacting with legitimate pages, potentially leading to credential theft or other social engineering attacks. The flaw is categorized as CWE‑682.
Affected Systems
Users of Google Chrome on Windows with browsers older than 155.0.8059.39 are impacted. The affected version 155.0.8059.39 contains the patch that addresses the calculation error.
Risk and Exploitability
Chromium assigns a medium severity to this CVE, and its CVSS score is 5.4. No EPSS score is available; it is not listed in the CISA KEV catalog. The likely attack vector is social engineering via a custom Chrome extension; an attacker must first persuade a user to install the malicious extension, after which the UI spoofing can deceive the user. While exploitation requires user interaction, the ease of distributing extensions elevates the risk to moderate or higher, especially for organizations that allow unrestricted extension installation.
OpenCVE Enrichment