Impact
The flaw is an inappropriate implementation of the same origin policy in Chrome for iOS. A crafted HTML page can cause the browser to treat content from a different domain as if it belonged to the original origin, allowing an attacker to read or manipulate cross‑origin data or execute malicious code. The vulnerability is remote and requires the victim’s browser to load the malicious page, and its assigned Chromium severity is low, but the potential for data theft remains.
Affected Systems
Google Chrome for iOS is affected, specifically all releases prior to 149.0.7827.53. The bug was addressed in version 149.0.7827.53 and later versions of Chrome for iOS.
Risk and Exploitability
There is no EPSS score available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, with the attacker supplying a malicious HTML page that a user must visited. Because exploitation requires user interaction, the likelihood of widespread automated attacks is currently low, but any user who encounters a crafted page in the affected browser could have sensitive web data exposed. The risk is moderate in environments where confidential or personal data is accessed via web applications on iOS devices.
OpenCVE Enrichment