Impact
The vulnerability is a side‑channel information leakage flaw in the Safe Browsing component of Google Chrome on iOS. If a remote attacker can compromise a renderer process, a specially crafted page can cause Chrome to reveal cross‑origin data that should not normally be disclosed. This flaw is classified as CWE‑1300 and permits the disclosure of sensitive information that a user has not explicitly shared.
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47 are affected. The vulnerability exists in the production releases of Chrome on iOS until the specified patch version is deployed; any earlier iOS build is considered vulnerable.
Risk and Exploitability
Exploitation requires the attacker to first gain control of the renderer process—typically by serving malicious web content—and then delivering a crafted HTML page to trigger the side‑channel. Based on the description, it is inferred that the attack vector is remote, web‑based, and contingent upon successful renderer compromise. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% shows a low but non‑zero likelihood of exploitation at this time. The issue is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA