Impact
Google Chrome for iOS contains a side-channel information leak in the WebAuthentication API that allows an attacker to obtain data from other origins. The defect, defined as CWE-1300, bypasses same‑origin restrictions so that a remote adversary can read sensitive information through a crafted HTML page. No code execution, privilege escalation, or denial of service is involved, but the confidentiality of data is compromised.
Affected Systems
All iOS devices running Chrome older than version 150.0.7871.47 are affected. The issue exists in every stable‑channel Chrome release until the browser is updated to the corrected build or the WebAuthentication API is disabled via policy.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting limited or no known widespread exploitation. Based on the description, the likely attack vector is a remote attacker hosting a malicious web page that triggers the WebAuthentication side‑channel; the compromised data remains across origins but remains confined to the information leakage scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA