Impact
The vulnerability is an inappropriate implementation in Chrome for iOS that permits a remote attacker to perform UI spoofing via a crafted HTML page. Identified as CWE-451, it does not grant direct code execution or data access but undermines user trust by allowing deceptive manipulation of the user interface.
Affected Systems
The flaw affects Google Chrome for iOS versions earlier than 150.0.7871.47. All current releases of the mobile browser that have not yet been updated to the patched build are susceptible. The vulnerability exists in the iOS implementation of the browser and applies to devices running those affected versions.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is classified as medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation, and it is not listed in the CISA KEV catalog. Attackers would host a malicious web page that triggers the forged UI; the attack requires only normal browsing activity from the victim and no special privileges. The likely attack vector is a crafted HTML page served over the internet.
OpenCVE Enrichment
Debian DLA
Debian DSA