Impact
The flaw resides in the iOSWeb component of Chrome for iOS, where insufficient validation of untrusted input permits a specially crafted HTML page to trigger heap corruption. This input‑validation weakness (CWE‑20) can lead to memory corruption that may be leveraged by an attacker for further compromise or execution of arbitrary code. The vulnerability is classified as Critical by Chromium security.
Affected Systems
All installations of Chrome for iOS running a build prior to 150.0.7871.47 are affected. While the description specifies iOS as the platform, it does not state a particular iOS version; we infer that every iOS version could be impacted as long as the Chrome build is older than 150.0.7871.47. Any user who loads a malicious HTML page in the browser on an affected device becomes a potential target.
Risk and Exploitability
The CVSS score of 8.8 indicates a high potential impact. The EPSS score of less than 1% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack vector requires a user to visit a malicious URL or load a crafted HTML document, meaning user interaction is necessary. No public exploits are known, so the overall risk is moderate, but the possible impact remains high if the flaw is successfully leveraged.
OpenCVE Enrichment
Debian DLA
Debian DSA