Impact
Side‑channel information leakage exists in WebAuthentication in Google Chrome on iOS before version 150.0.7871.47. A crafted HTML page can trigger the browser to unintentionally expose data that originates from a different origin. The primary impact is unauthorized disclosure of information from the victim device, reflecting a CWE‑20 input validation weakness.
Affected Systems
Google Chrome on iOS, versions prior to 150.0.7871.47 contain the vulnerability; later releases include the fix.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score is less than 1%, and the vulnerability is not listed in CISA KEV, so exploitation likelihood is very low. The attack vector is presumed remote, via a malicious web page that the user visits, after which the flaw allows cross‑origin data exfiltration.
OpenCVE Enrichment
Debian DLA
Debian DSA