Impact
Chrome for iOS implements rendering incorrectly, which allows a remote attacker to perform UI spoofing through a crafted HTML page. The flaw permits the browser to overlay or render user interface elements that mimic the browser’s native controls, potentially disguising malicious content. This weakness is categorized as information exposure (CWE‑451). Based on the description, it is inferred that an attacker can trigger the flaw by delivering a crafted HTML page to a victim’s browser.
Affected Systems
Any Google Chrome for iOS build older than version 150.0.7871.47 is affected. This includes all iOS devices running Chrome before that update, regardless of brand or carrier.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, and the EPSS score of less than 1% reflects an extremely low likelihood of exploitation. The vulnerability is not in CISA’s KEV catalog. Exploitation requires only that a victim open a crafted HTML page in Chrome; no local privileges or additional setup are needed. The impact is limited to user deception and potential phishing, which does not compromise confidentiality or integrity of the device or data beyond possible user credential fields. The likely attack vector is inferred to be remote access via a crafted HTML page opened in Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA