Impact
A code injection flaw in the ReaderMode feature of Google Chrome on iOS allows an attacker to craft an HTML page that, when opened by a user, injects code that bypasses the browser’s same‑origin policy. By doing so, the attacker can read or modify content from the victim’s browsing context, potentially exfiltrating data or performing unauthorized actions. This is a classical Code Injection weakness, CWE‑94, and could compromise both confidentiality and integrity for the user’s data.
Affected Systems
Users of Google Chrome on iOS running versions earlier than 155.0.8059.39 are affected. No other products are listed, and the issue is confined to the ReaderMode mode in those releases.
Risk and Exploitability
The Chromium severity for this flaw is Medium, indicating a moderate risk. No CVSS score is disclosed and the EPSS score is not available, so exploitation likelihood is considered moderate. The vulnerability is not listed in the CISA KEV catalog. An attacker would need to lure the user into opening a crafted HTML page, typically via social engineering such as phishing links. As no public exploit code is known, the overall risk remains moderate, but the potential impact is significant if the attack succeeds.
OpenCVE Enrichment