Impact
Use‑after‑free in Chrome’s import feature on a crafted file and performs specific UI gestures. The flaw, a CWE‑416 vulnerability, is limited to versions before 150.0.7871.47 and provides an attacker the ability to run code on the device, compromising confidentiality, integrity, and availability.
Affected Systems
Google Chrome on iOS, versions older than 150.0.7871.47
Risk and Exploitability
With a CVSS score of 7.5, the flaw is rated as high severity. The EPSS score of less than 1% indicates that the likelihood of exploitation is low, and the vulnerability is not listed in the CISA KEV catalog. If an attacker successfully induces a user to open a crafted file and trigger the import feature, the use‑after‑free can lead to arbitrary code execution with the device’s privileges. Because exploitation requires social engineering in addition to a compatible file, overall risk is moderate, but a patched version must be installed promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA