Impact
Insufficient validation of untrusted input in Chrome for iOS enables a remote attacker, by persuading a user to perform targeted UI gestures after visiting a crafted web page, to carry out UI spoofing. The attacker can make legitimate controls appear as malicious prompts, facilitating phishing or deceptive interactions. This is an input validation weakness (CWE‑20) that does not provide code execution or data exfiltration.
Affected Systems
Google Chrome for iOS versions earlier than 150.0.7871.47 are affected. The vulnerability applies only to that browser; the description does not indicate that other iOS browsers using the same WebView component are impacted.
Risk and Exploitability
The CVSS score of 4.2 denotes a low impact, and the EPSS score is below 1 %, indicating a low probability of widespread exploitation. Attackers would need to convince a user to perform specific gestures on a malicious site; no direct code execution is required. The vulnerability is not listed in the CISA KEV catalog, further suggesting limited real‑world exploitation. Updating to Chrome 150.0.7871.47 or later removes the flaw.
OpenCVE Enrichment
Debian DLA
Debian DSA