Impact
A discrepancy in Safebrowsing processing on iOS versions of Google Chrome prior to 155.0.8059.39 allowed a remote attacker who could compromise the renderer process to craft a malicious HTML page and exfiltrate sensitive data. The flaw falls under the input validation weakness identified as CWE‑203 and results in the disclosure of information that may be considered confidential to the user. The Chromium security severity is rated as Medium.
Affected Systems
All users of Google Chrome on iOS devices running a version earlier than 155.0.8059.39 are potentially vulnerable. The issue is specific to the renderer component and does not affect other browser components directly.
Risk and Exploitability
The vulnerability is not currently listed in the CISA KEV catalog and no EPSS score is available, indicating limited publicly known exploitation. The CVSS score of 5.3 classifies it as Medium severity. Exploitation requires an attacker to first compromise the renderer process, which would involve a separate chain of attack steps. Once that control is achieved, the attacker can serve a crafted HTML page to harvest data. Because the weakness is limited to information disclosure and does not grant arbitrary code execution, the overall risk remains Medium pending the adoption of the fix.
OpenCVE Enrichment