Impact
Insufficient data validation in Google Chrome for iOS allows a local attacker who has physical access to the device to read potentially sensitive information from the process memory. The flaw maps to improper input validation (CWE‑20).
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47 are affected.
Risk and Exploitability
The exploit requires direct physical access to the device, so it is a local attack. The CVSS score of 4.6 indicates a moderate impact level. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. While no public exploit exists, the Chromium security assessment labels it as high severity, underscoring the potential compromise of confidential data if an attacker succeeds.
OpenCVE Enrichment
Debian DLA
Debian DSA