Impact
An improper implementation in Chrome for iOS allows a remote attacker to trigger a crafted HTML page that forces the browser to expose data from other origins, thereby leaking sensitive information and violating user confidentiality; the issue is classified as a medium severity flaw by Chromium and is identified as CWE-346 and CWE-352.
Affected Systems
Google Chrome for iOS versions older than 149.0.7827.53 are affected, impacting all iOS devices using those builds.
Risk and Exploitability
The CVSS score is 6.5, indicating medium severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, so widespread exploitation has not been documented. However, an attacker can still leak cross-origin data when a user opens a malicious web page on an impacted device. The risk remains moderate because it requires user interaction.
OpenCVE Enrichment
Debian DSA