Impact
Inappropriate implementation in Chrome’s DOM Distiller on iOS enables a remote attacker to bypass navigation restrictions by delivering a specially crafted HTML page. The vulnerability allows the attacker to cause Chrome to navigate to URLs that would normally be blocked, thereby potentially exposing the user to malicious content or phishing. The weakness is an improper enforcement of navigation limits, which could be leveraged to subvert the browser’s security model.
Affected Systems
Google Chrome for iOS versions earlier than 149.0.7827.53
Risk and Exploitability
The vulnerability is classified with low severity by Chromium, and no EPSS score is available. It is not listed in the CISA KEV catalog. A remote attacker can trigger the flaw by forcing a user to open the crafted HTML page, so the attack vector is remote over the web. Because the issue is client‑side and requires the user to touch the page, the exploitation probability is uncertain but not negligible for targeted campaigns. Until the browser is updated, users remain vulnerable to navigation‑based attacks.
OpenCVE Enrichment