Impact
Chrome for iOS versions earlier than 150.0.7871.47 contain interface elements that appear legitimate to users. This flaw is identified as CWE‑451, meaning a crafted HTML page can simulate user interfaces such that a user may be deceived into interacting with a false dialog box or form. The attacker can thus trick a user into entering sensitive information. The vulnerability does not enable arbitrary code execution or device compromise; it is limited to UI deception, consistent with the CVSS score of 4.3.
Affected Systems
All builds of Google Chrome for iOS prior to version 150.0.7871.47 are affected. Later releases contain the correction and are therefore not vulnerable.
Risk and Exploitability
The vulnerability can be exploited through a remote crafted HTML page, giving an attacker the ability to perform UI spoofing. The moderate CVSS score indicates a non‑critical risk, while the EPSS score of less than 1% reflects a very low likelihood of exploitation in the wild. Because the vulnerability is not listed in the CISA KEV catalog, no widespread exploits are documented. The attack vector is remote, governed by the web interface, and the impact is limited to user deception rather than system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA