Impact
The flaw stems from an inappropriate implementation in Chrome for iOS prior to 150.0.7871.47 that allows a remote attacker to inject a crafted HTML page causing the Omnibox, the URL bar, to display spoofed information. This deception is purely visual; it does not grant code execution or system modification. The weakness corresponds to CWE‑451, indicating inadequate validation of the input source, and the CVSS score of 4.3 classifies the issue as low severity.
Affected Systems
Affected users are those running Google Chrome for iOS before version 150.0.7871.47. The vulnerability is limited to the iOS edition of Chrome; desktop, Android, or other platform versions are not affected.
Risk and Exploitability
The EPSS score of less than 1% indicates a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widely known attacks. The likely attack vector is that an attacker serves a malicious HTML page to a victim who opens it in Chrome for iOS; upon viewing, the browser shows a spoofed Omnibox that could lead to phishing or credential theft. The impact is confined to deception and potential credential compromise with no code execution or system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA