Impact
An improper implementation of ScriptInjections in Google Chrome on iOS prior to version 150.0.7871.47 allows a remote attacker to craft an HTML page that causes the browser to retrieve and expose data from another origin, breaking the same‑origin policy. The weakness is identified as a cross‑site request forgery (CWE-352) and results in potential data leakage.
Affected Systems
All installations of Google Chrome on iOS earlier than version 150.0.7871.47 are affected, regardless of whether the device is a consumer or enterprise environment.
Risk and Exploitability
Chromium rates the flaw as Medium severity with a CVSS score of 4.3. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker that serves a crafted HTML page to the victim, triggering the script injection without requiring elevated privileges. The threat is thus limited to data leakage from cross‑origin sources.
OpenCVE Enrichment
Debian DLA
Debian DSA