Impact
An improper input validation routine in the Signin component of Google Chrome for iOS allows a malicious webpage to masquerade as the legitimate sign‑in interface. By serving a crafted HTML page, a remote attacker can trick a user into entering credentials or other sensitive information into a spoofed form. The flaw does not provide code execution or direct data exposure, but it can facilitate phishing or credential theft if the user believes the page is genuine.
Affected Systems
Google Chrome for iOS builds older than 149.0.7827.53 are affected. All iOS deployments running these earlier revisions are vulnerable to the UI spoofing vulnerability.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS score below 1% indicate low overall severity, but the attack remains remotely exploitable via a crafted web page. Successful exploitation requires social engineering to lure a user to the malicious page. Because the vulnerability does not grant arbitrary code execution, the potential damage is limited to credential compromise or unintended user interactions. The flaw is not listed in the CISA KEV catalog, and a patched release is available, mitigating the risk for users who stay up to date.
OpenCVE Enrichment
Debian DSA