Impact
The flaw is a missing authorization check in Google Chrome for iOS. A remote attacker can send a victim a crafted HTML page that, if the victim visits it, may execute arbitrary code outside the browser sandbox. This represents a high‑severity problem per Chromium’s own ratings, exposing the user to full system compromise if the vulnerability is exercised.
Affected Systems
Google Chrome for iOS versions prior to 155.0.8059.39 are vulnerable. All users running those builds on iOS devices are at risk until they upgrade to the patched release.
Risk and Exploitability
The vulnerability is exploitable when a user is tricked into opening a malicious web page, indicating a social‑engineering attack vector. No EPSS score is publicly available, and the exploit is not listed in CISA’s KEV catalog, but the CVSS score of 9.6 and the potential for arbitrary code execution suggest a significant risk if not patched.
OpenCVE Enrichment