Impact
The vulnerability arises from insufficient validation of untrusted input in Chrome for iOS. A remote attacker can craft a malicious HTML page that, when opened in the browser, creates counterfeit user interface elements. This allows UI spoofing, enabling the attacker to trick users into performing unintended actions, potentially facilitating phishing or other malicious interactions. Based on the description, it is inferred that the attacker relies on delivering the crafted HTML page to the user’s browser, which serves as the primary attack vector.
Affected Systems
Google Chrome for iOS versions before build 150.0.7871.47 are affected. Users who have not upgraded beyond that build remain at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity. The EPSS score of less than 1% shows a very low probability that this vulnerability is being exploited in the wild. The flaw is not listed in the CISA KEV catalog. An attacker only needs to host a malicious web page and persuade a user to load it in Chrome on iOS; no elevated privileges or additional software are required. The likely attack vector is a malicious HTML page loaded by a user in Chrome for iOS, requiring the victim to open the crafted page in an affected version of the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA