Impact
The vulnerability is a misuse of the Omnibox rendering in Chrome for iOS that allows a remote attacker to spoof the URL bar using a crafted HTML page. It is classified as CWE-451 (UI Deception). This UI deception may mislead users into believing they are viewing a legitimate site, enabling phishing or credential‑stealing attacks, as inferred from the nature of the deception described.
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47, regardless of the release channel, are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation. The attack requires a malicious website and user interaction to trigger the Omnibox spoofing. Because the vulnerability does not compromise system integrity or confidentiality, it is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA