Impact
An inappropriate implementation in Chrome for iOS permits a remote attacker to cause the Omnibox (URL bar) to display a spoofed address. The attacker does this by hosting a crafted HTML page and inducing the user to perform specific UI gestures. When these gestures are performed, the browser renders a different URL than the page actually loaded, creating a visual deception that could erode user trust. Based on the description, it is inferred that this deception could lead to phishing or social‑engineering attacks, although the vulnerability itself does not provide code execution or data exfiltration.
Affected Systems
Google Chrome for iOS versions older than build 150.0.7871.47 are affected. Users with those earlier Chrome for iOS installations are susceptible when they visit a maliciously crafted web page that can trigger the required gestures.
Risk and Exploitability
The CVSS score of 4.2 places the vulnerability in the medium severity range, while the EPSS score of < 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is remote via a crafted HTML page, but based on the description, it is inferred that the attacker must persuade the user to perform the defined gestures, limiting automated exploitation possibilities.
OpenCVE Enrichment
Debian DLA
Debian DSA