Impact
Chrome for iOS suffers from insufficient validation of untrusted input, allowing a remote attacker to craft an HTML page that can mimic or overlay legitimate user interface components. The flaw, classified as a CWE‑451 weakness, can deceive users into interacting with deceptive elements, potentially leading to unintended actions or credential disclosure. Chromium has rated the issue as low severity.
Affected Systems
The vulnerability affects Google Chrome for iOS versions earlier than 150.0.7871.47. No other vendors or products are impacted.
Risk and Exploitability
The CVSS score of 4.3 reflects a low severity rating, and the EPSS score of less than 1 % indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because the weakness operates during the rendering of untrusted HTML, the most likely attack requires a victim to view a maliciously crafted page in Chrome, after which the attacker can perform UI spoofing. No privileged access is needed beyond the normal user’s interaction with the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA