Impact
The flaw stems from an inappropriate implementation in Chrome for iOS prior to 150.0.787 attacker to serve a crafted HTML page that displays a spoofed Omnibox. The deception is purely visual, causing users to believe they are on a different web site and potentially leading to phishing attempts or credential compromise. This weakness corresponds to CWE‑451, which denotes inadequate validation of the source of input.
Affected Systems
Affected users are those running Google Chrome for iOS prior to version 150.0.7871.47. The vulnerability is limited to the iOS edition of Chrome; desktop, Android, or other platform versions are not affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity. The EPSS score is less than 1%, indicating a very small probability of exploitation. The CVE is not recorded in the CISA KEV catalog, suggesting no publicly known exploitation. Based on the description, it is inferred that the attacker would need to provide a malicious HTML page to a victim who opens it in Chrome for iOS. Once viewed, the browser shows a facilitating phishing. The impact is limited to deception and possible credential theft, with no code execution or system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA