Impact
The vulnerability lies in the iOSWeb component of Chrome for iOS, where insufficient validation of untrusted input enables a specially crafted HTML page to trigger heap corruption. This input‑validation weakness (CWE‑20) is classified as Critical by Chromium. The CVE notes that a remote attacker could potentially exploit the heap corruption, but no further outcome such as code execution is described in the official data.
Affected Systems
All installations of Chrome for iOS that use a build older than 150.0.7871.47 are impacted. The description refers only to iOS, but no iOS version is specified, so every iOS installation running an affected Chrome build is at risk. Users who open a malicious HTML page in Chrome on a vulnerable device could trigger the crash.
Risk and Exploitability
The CVSS score of 8.8 indicates a high potential impact. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack requires a user to load a malicious HTML page or visit a malicious URL within Chrome, so interaction is needed. No public exploits have been reported, so the current risk can be considered moderate while the potential impact remains high.
OpenCVE Enrichment
Debian DLA
Debian DSA