Impact
Chrome for iOS contains a flaw in policy enforcement that allows a remote attacker to bypass navigation restrictions by serving a crafted HTML page. The issue maps to CWE‑602 and enables the browser to navigate to URLs that would normally be blocked, potentially exposing users to malicious sites. The description indicates that the attacker must supply a malicious HTML page that the user opens, so user interaction is required, which is inferred from the provided details.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected; no other operating systems or variants are impacted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The attack requires a malicious HTML page that the user must open, so user interaction is needed. Successful exploitation causes the browser to navigate to previously blocked URLs, which could lead to phishing or other malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA