Impact
Chrome for iOS versions earlier than 150.0.7871.47 contain a flaw that can be exploited by an attacker to display UI elements that appear legitimate to the user. This flaw is classified as CWE‑451, indicating that a crafted page can simulate user interfaces and deceive users. For example, the attacker can impersonate dialog boxes or form prompts to trick users into entering sensitive information. The vulnerability does not provide arbitrary code execution or device compromise; its effect is limited to UI deception, as reflected in a CVSS score of 4.3.
Affected Systems
All builds of Google Chrome for iOS prior to version 150.0.7871.47 are affected. It is not confirmed whether later releases contain the fix.
Risk and Exploitability
Based on the description, it is inferred that a malicious web page can trigger the UI spoofing remotely without further prerequisites. The EPSS score of less than 1% indicates a very low likelihood of exploitation, and the CVSS score of 4.3 denotes medium severity. The vulnerability is not listed in the CISA KEV catalog. The impact is confined to user deception rather than code execution or device compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA