Impact
Insufficient validation of untrusted input (CWE-20) in Chrome for iOS prior to 150.0.7871.47 permits a remote attacker who persuades a user to perform specific UI gestures to inject arbitrary scripts or HTML via a crafted page. This enables the attacker to execute arbitrary code within the context of the victim’s browsing session, but does not elevate privileges beyond the browser.
Affected Systems
Google Chrome for iOS versions less than 150.0.7871.47 are vulnerable.
Risk and Exploitability
The CVSS score of 4.7 indicates moderate impact, and the EPSS score of < 1% suggests a low probability of exploitation. The flaw is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a malicious webpage and perform a predefined sequence of UI gestures, which relies on social engineering and does not provide remote code execution or privilege escalation beyond the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA