Impact
The flaw exists in the iOSWeb renderer of Google Chrome for iOS before version 150.0.7871.47, where an incorrect UI rendering implementation permits a crafted web page display that mimics legitimate elements. It can deceive users into interacting with fake controls or revealing sensitive information, but it does not provide code execution or direct system compromise. The weakness is classified as CWE‑451.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected when a malicious page forces the user to perform specific touch gestures.
Risk and Exploitability
Exploitation requires delivery of a malicious site and user cooperation to perform specific gestures. The CVSS score of 4.2 indicates medium‑severity user‑deception impact. An EPSS score of less than 1% suggests a low probability of real‑world exploitation, and the vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation. Attack difficulty remains moderate because it relies on social engineering to trigger the user’s gestures.
OpenCVE Enrichment
Debian DLA
Debian DSA