Impact
The documented vulnerability originates from an inappropriate Safe Browsing implementation (CWE-451) in the mobile browser on iOS. An attacker can serve a crafted web page that renders a forged user interface, allowing the user to interact with deceptive controls that appear legitimate. Because the flaw resides in how the engine displays content, it does not provide code execution or direct data theft; its impact is limited to deceptive visual interaction with the user.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected. No information is provided about impacts on Chrome for other operating systems such as Android, Windows, or macOS.
Risk and Exploitability
The rating attached to this issue is a CVSS score of 4.3, classifying it as medium severity. The exploit probability indicated by the EPSS score is less than 1%, which suggests that active exploitation is unlikely at present. The flaw likely requires a remote attacker to host a malicious web page that a user visits in a vulnerable Chrome iOS browser; the attacker's success depends on user interaction with the spoofed interface. The issue is not listed in the CISA Known Exploited Vulnerabilities catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA