Impact
An inappropriate implementation in Chrome for iOS allows a remote attacker to perform UI spoofing via a crafted HTML page. The flaw, classified as CWE-451, enables an attacker to overlay or manipulate the browser’s visual interface, potentially misleading users about the authenticity of displayed content. The CVE data does not indicate code execution; the impact is limited to UI manipulation.
Affected Systems
Affected systems include all iOS devices running Google Chrome versions earlier than 150.0.7871.47. The vulnerability is present in the iOS build of Chrome and affects all installations without the patch.
Risk and Exploitability
The CVSS score of 4.3 indicates medium impact, while the EPSS score of less than 1 % points to a low probability of exploitation. The vulnerability is not included in CISA's KEV catalog. The likely attack vector is a web‑based exploit where an attacker hosts a malicious page and lures a user into opening it under an unpatched Chrome for iOS. In such a scenario, the attacker can manipulate the UI to deceive the user.
OpenCVE Enrichment
Debian DLA
Debian DSA