Impact
Insufficient policy enforcement in Google Chrome for iOS allows a remote attacker who has already compromised the renderer process to perform a sandbox escape by serving a crafted HTML page (CWE-20). This flaw enables the attacker to execute code outside the browser sandbox and potentially take control of the device, compromising confidentiality, integrity, and availability of the user’s data in the affected environment.
Affected Systems
Google Chrome for iOS builds prior to version 150.0.7871.47 are affected. Users running these builds may be exposed if they view malicious web content that could trigger the sandbox escape. Based on the description, it is inferred that exposure requires delivery of crafted HTML that first compromises the renderer.
Risk and Exploitability
With a CVSS score of 8.3, an EPSS score of < 1% indicates a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. An attacker must first compromise the renderer process and then serve crafted HTML to trigger the sandbox escape, which in turn requires the user to interact with malicious sites.
OpenCVE Enrichment
Debian DLA
Debian DSA