Impact
The vulnerability is an inappropriate implementation in Chrome for iOS that permits a remote attacker to perform UI spoofing via a crafted HTML page. This flaw is identified as CWE-451. The impact is deceptive manipulation of the user interface and does not grant direct code execution or data access; it only undermines user trust.
Affected Systems
The flaw affects Google Chrome for iOS versions earlier than 150.0.7871.47. All current releases of the mobile browser that have not yet been updated to the patched build are susceptible. The vulnerability exists in the iOS implementation of the browser and applies to devices running those affected versions.
Risk and Exploitability
With a CVSS score of 4.3 the vulnerability is classified as medium severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the CISA’s KEV catalog. Attackers would host a malicious web page that triggers the forged UI; the attack requires only normal browsing activity from the victim and no special privileges. The likely attack vector is a crafted HTML page served over the internet.
OpenCVE Enrichment
Debian DLA
Debian DSA