Impact
An inappropriate implementation in Chrome for iOS permits a malicious web page to trigger UI gestures that grant the browser access to read data from a different origin. This flaw, aligned with CWE‑451, results in a confidentiality breach by leaking cross‑origin data to an attacker. No remote code execution or system compromise is known.
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score is 6.5, indicating moderate severity, while the EPSS score of less than 1% shows a low probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers must deliver a malicious page and convince a user to perform specific UI gestures; the requirement for user interaction reduces the likelihood of automated exploitation, yet the flaw remains a concern for users visiting untrusted sites.
OpenCVE Enrichment
Debian DLA
Debian DSA