Impact
The vulnerability is an input‑validation weakness identified as CWE‑20. It allows a remote attacker to craft a malicious HTML page that, when rendered by Chrome for iOS, creates counterfeit user interface elements, enabling the attacker to trick a user into performing unintended actions. This results in UI spoofing that compromises the integrity of the user interface and can be used for phishing or other malicious interactions.
Affected Systems
Google Chrome for iOS versions prior to build 150.0.7871.47 are affected. Users who have not upgraded from this build remain at risk.
Risk and Exploitability
With a CVSS score of 4.3 the severity is classified as medium, and an EPSS score of less than 1 % indicates a low likelihood of real‑world exploitation. The flaw is not listed in the CISA KEV catalog. An attacker only needs to host a malicious webpage and convince a user to open it in Chrome on iOS; based on the description, it is inferred that no additional permissions or elevated privileges are required.
OpenCVE Enrichment
Debian DLA
Debian DSA