Impact
A flaw in Chrome on iOS’s ScriptInjections component lets attackers create an HTML page that causes the browser to retrieve and expose data from a different origin. The vulnerability breaks the same origin policy, allowing potentially sensitive user information such as personal data or credentials to be leaked. The weakness stems from an improper implementation of script injection handling, which is identified as a cross‑site request forgery (CWE‑352).
Affected Systems
The issue affects every Google Chrome installation on iOS devices that has not yet applied the latest stable channel update. Users who have not applied the stable channel update are exposed, regardless of enterprise or consumer deployment.
Risk and Exploitability
Chromium rates the flaw as Medium severity and the publicly available CVSS score is 4.3. The EPSS score is <1% and the’s KEV catalog, indicating that no confirmed exploits are known. The likely attack vector is a malicious; viewing such a page can trigger the leak without elevated privileges, presenting a non‑negligible risk for unsuspecting users.
OpenCVE Enrichment
Debian DLA
Debian DSA