Impact
A use‑after‑free bug in Google Chrome for iOS allows a remote attacker to craft an HTML page that triggers the faulty memory reference, enabling arbitrary code execution on the victim device. The flaw is classified as CWE‑416, indicating that a program mistakenly uses freed memory, leading to unpredictable behavior. Attackers could gain full control of the browser process, potentially compromising the device, leaking personal data, or installing malware without user consent.
Affected Systems
Google’s Chrome for iOS versions earlier than 149.0.7827.53 are vulnerable. The affected build includes the iOS runtime, and any device running the specified pre‑update version could be compromised if exposed to a malicious webpage.
Risk and Exploitability
The reported severity is marked as Critical by Chromium. EPSS information is not available, and the vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is remote via a crafted HTML page viewed in the vulnerable browser, so any web traffic that could contain malicious content poses a threat. Exploitation would require the victim to open the malicious page and the attacker would then gain code‑execution privileges on the device.
OpenCVE Enrichment