Impact
The weakness arises from an inappropriate implementation in iOSWeb within Chrome on iOS before 150.0.7871.47, classified as CWE-451. This flaw allows a remote attacker who persuades a user to perform specific touch gestures to trigger UI spoofing through a crafted HTML page. The result is a deceptive interface that mimics legitimate UI elements, enabling user deception without exploiting input validation or memory corruption.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected.
Risk and Exploitability
Exploitation requires a crafted web page delivered to a vulnerable iOS device and convincing the user to perform the required gestures. Once engaged, the attacker can display a spoofed UI that may lead the user to interact with malicious controls. The CVSS score of 4.2 indicates medium severity, the EPSS score of < 1% shows a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV, suggesting moderate but tangible risk dependent on user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA