Impact
This vulnerability results from insufficient enforcement of the no‑referrer policy in Google Chrome for iOS. By serving a crafted HTML page, an attacker can cause Chrome to transmit the Referrer header even when the policy is enabled, revealing the originating site to external parties. The flaw exposes browsing context without granting code execution or elevated privileges, focusing solely on privacy disclosure.
Affected Systems
The flaw impacts devices running Google Chrome for iOS prior to build 150.0.7871.47; any installation that has not applied this update is susceptible.
Risk and Exploitability
Based on the description, it is inferred that a remote attacker can host a crafted HTML page, and a victim who loads that page in Chrome for iOS will trigger the browser to send a Referrer header despite the no‑referrer policy, disclosing the origin to external parties. The victim must merely visit the malicious page; no local privileges or additional conditions are required. The CVSS score of 4.3 indicates low overall severity, and the EPSS score of < 1% shows an extremely low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. While the Chromium severity is low, the privacy exposure can be significant.
OpenCVE Enrichment
Debian DLA
Debian DSA