Impact
The vulnerability is an input validation flaw (CWE‑20) in Chrome for iOS. Untrusted HTML input is insufficiently validated, allowing a crafted web page to cause the browser to ignore its internal navigation restrictions. An attacker who can deliver such a page and convince a user to perform specific UI gestures can make the browser navigate to arbitrary sites or content that the user would normally be prevented from accessing.
Affected Systems
Google Chrome for iOS versions prior to 150.0.7871.47 are affected. No other Chrome for iOS releases are known to have this flaw.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity vulnerability. The EPSS score is below 1 %, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack description suggests that exploitation requires delivering a malicious HTML page and convincing a user to perform specific UI gestures; it is inferred that user participation is necessary and the exploit cannot be fully automated, reducing the risk of widespread attacks at present.
OpenCVE Enrichment
Debian DLA
Debian DSA