Impact
Google Chrome for iOS contains a flaw in the Omnibox that permits a remote attacker to inject arbitrary scripts or HTML into a page viewed by the victim. The injection is achieved when the victim performs a specific UI gesture following by a malicious page. The code runs in the context of the page, enabling malicious actions. This vulnerability is a form of cross‑site scripting (CWE‑79).
Affected Systems
Chrome browsers on iOS running versions earlier than 150.0.7871.47 are vulnerable. The fix is included in Chrome iOS 150.0.7871.47 and later. Users on older releases, or those who have not updated, remain at risk.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS score of less than 1 % points to a low probability of exploitation. CISA’s KEV catalog, suggesting no large‑scale attacks have been observed. Based on the description, it is inferred that the attacker must convince a user to execute a specific gesture in Chrome’s interface, after which the injected script runs. Thus exploitation requires social engineering and is unlikely to be a widespread automated attack.
OpenCVE Enrichment
Debian DLA
Debian DSA