Impact
The vulnerability exposes a side‑channel within the Safe Browsing component of Google Chrome on iOS. If an attacker can compromise the renderer process, a specially crafted HTML page can trigger the browser to reveal data that ordinarily would be protected by the same‑origin policy. This side‑channel information leak (CWE‑1300) enables the disclosure of cross‑origin data, undermining the browser’s isolation guarantees.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected. The CVE listing does not specify additional patches beyond that version, so any iOS build older than the latest released Chrome should be assumed vulnerable until an explicit update is confirmed.
Risk and Exploitability
The CVSS score of 6.5 reflects a moderate severity. An EPSS score of less than 1% indicates a low but non‑zero probability of exploitation at present. The vulnerability is not in CISA’s KEV catalog. Exploitation requires the attacker first to gain control of a renderer process—likely through malicious web content or phishing attempts—and then to serve a crafted HTML page to activate the side‑channel. The attack vector is remote, web‑based, and contingent upon the renderer compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA