Impact
An inappropriate implementation in Chrome for iOS versions prior to 149.0.7827.53 allows a remote attacker to craft an HTML page that mimics legitimate browser UI elements (CWE-451). The flaw enables a spoofed interface that may display deceptive content, potentially misleading users during interaction with the browser.
Affected Systems
Chrome for iOS running any build older than 149.0.7827.53 is vulnerable. The issue does not affect Chrome on desktop platforms or other browsers on iOS.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS score of < 1% indicate a low likelihood of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring the victim to load a maliciously crafted web page in Chrome for iOS. While the risk of direct code execution is minimal, a deceptive interface could lead to user confusion or inadvertent interaction with malicious content, as inferred from the nature of UI spoofing.
OpenCVE Enrichment
Debian DSA