Impact
Google Chrome for iOS before build 150.0.7871.47 has insufficient policy enforcement for the Web Authentication (Passkeys & Security Keys) API, which allows an attacker from a privileged network to trigger a crafted HTML page that can leak cross‑origin data. The weakness is a protection mechanism failure (CWE‑693). The impact is limited to confidentiality, as it permits leakage of data from a different origin without granting code execution or privilege escalation. The medium‑severity CVSS score of 6.5 reflects the restricted scope.
Affected Systems
All Chrome iOS installations built before 150.0.7871.47 are affected. No other platforms are confirmed to be impacted.
Risk and Exploitability
Exploitation requires an attacker to serve the malicious HTML from a privileged network and convince a user to visit it. The EPSS score of <1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Attackers cannot gain code execution or escalated privileges; their objective is to read cross‑origin data that is protected by the Web Authentication policy.
OpenCVE Enrichment
Debian DLA
Debian DSA