Impact
The vulnerability is an inappropriate handling of the Omnibox rendering in Google Chrome for iOS that allows a remote attacker to spoof the contents of the URL bar using a crafted HTML page. This UI deception, classified as CWE‑451, may mislead users into believing they are viewing a legitimate site, potentially enabling phishing or credential‑stealing attacks; these effects are inferred from the nature of the deception described.
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47, regardless of the release channel, are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The attack requires a malicious website and user interaction to trigger the Omnibox spoofing. Because the vulnerability does not compromise system integrity or confidentiality, it is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA