Impact
An inappropriate implementation in the Omnibox component of Google Chrome for iOS versions earlier than 150.0.7871.47 allows a remote attacker to inject arbitrary scripts or HTML through a crafted page after a user performs a specific UI gesture. The vulnerability is categorized as a User Interaction–Triggered Script Injection (UXSS) and is associated with CWE-79.
Affected Systems
Google Chrome for iOS older than version 150.0.7871.47 is affected. The flaw is removed in the 150.0.7871.47 release and later.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity, and the EPSS score of less than 1 % reflects a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, suggesting that no large‑scale incidents have been reported. Exploitation requires a user to be persuaded to perform the specific UI gesture after visiting a malicious page, indicating that the attack vector is user‑interaction dependent.
OpenCVE Enrichment
Debian DLA
Debian DSA