Impact
A use‑after‑free flaw in Google Chrome for iOS versions prior to 149.0.7827.53 allows a remote attacker to craft a malicious HTML page that triggers heap corruption, potentially enabling arbitrary code execution or other disruptive behavior on the device. This flaw is categorized as CWE‑416, a memory management vulnerability that can lead to complete compromise of confidentiality, integrity, or availability of the affected system.
Affected Systems
All iOS installations of Google Chrome running a version older than 149.0.7827.53 are affected. The vulnerability is specific to Chrome for iOS and applies to every device that has not yet updated to the patched release.
Risk and Exploitability
The issue carries a high severity rating from Chromium, and although an EPSS score is not available, the potential for exploiting the flaw through a crafted web page is evident. The attack vector is remote, relying on user interaction with a maliciously designed website; according to the description, the exploit does not explicitly involve cross‑site scripting, but this statement is inferred. The lack of a public exploit at this time does not diminish the risk posed by the high‑confidence severity assessment.
OpenCVE Enrichment