Impact
Insufficient validation of untrusted input (CWE-20) in Chrome for iOS prior to 150.0.7871.47 permits a remote attacker who persuades a user to perform specific UI gestures to inject arbitrary scripts or HTML via a crafted page. This enables the attacker to execute arbitrary code within the context of the victim’s browsing session, but does not elevate privileges beyond the browser context.
Affected Systems
Google Chrome for iOS versions less than 150.0.7871.47 are vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate impact, and the EPSS score of < 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a crafted page and perform specific UI gestures upon the attacker’s instruction, which relies on social engineering. Once engaged, the attacker can inject and execute arbitrary scripts within the browsing context, providing in‑browser code execution but not system‑level privilege escalation.
OpenCVE Enrichment
Debian DLA
Debian DSA