Impact
Insufficient policy enforcement in Chrome for iOS allowed a remote attacker to bypass discretionary access control using a crafted HTML page. The flaw permits elevated privileges or unauthorized data access without needing local exploitation. The Chromium severity assessment labels it as low, indicating that the vulnerability’s impact is limited but still present.
Affected Systems
Google Chrome for iOS is affected. No specific version is listed, but the issue applies to releases prior to 149.0.7827.53.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, suggesting a low likelihood of widespread exploitation. Nevertheless, a remote attacker could supply a malicious HTML page to a victim who opens it in Chrome for iOS, leveraging the policy enforcement weakness to gain unauthorized access or manipulate data. The absence of a CVSS score in the public data means the exact severity cannot be quantified, but the Chromium low severity rating and the nature of the access control bypass point to a moderate risk for impacted users who regularly encounter untrusted web content.
OpenCVE Enrichment