Impact
Insufficient policy enforcement in the Autofill feature of Google Chrome on iOS before version 150.0.7871.47 allows a remote attacker to cause the browser to leak cross‑origin data. By persuading a user to perform specific, user‑initiated UI gestures on a crafted web page, the attacker can extract information that should remain isolated to other origins. The weakness is identified as a CWE‑346 Information Exposure vulnerability, affecting the browser’s ability to enforce origin isolation and potentially exposing sensitive data.
Affected Systems
Google Chrome on iOS in releases prior to 150 is affected. The vulnerability arises in the Autofill component and impacts the browser’s ability to enforce origin isolation for form data. Users of older Chrome for iOS versions are susceptible until a patch is applied.
Risk and Exploitability
The CVSS rating describes a medium‑severity flaw; exploitation requires the victim to interact with a malicious page, implying a user‑interaction prerequisite. The EPSS score is < 1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. While the attack vector is remote (user loads the page), the need for user gestures lowers the likelihood of automated exploitation but does not eliminate it.
OpenCVE Enrichment
Debian DLA
Debian DSA