Impact
The flaw in Google Chrome for iOS allows a malicious web page to display a counterfeit password prompt that mimics the authentic dialog. When a user enters credentials into this forged prompt, the attacker can capture the login information. The weakness is classified as CWE‑451. No arbitrary code execution or system compromise can be achieved; the vulnerability solely permits deception and credential leakage.
Affected Systems
Chrome for iOS versions prior to 150.0.7871.47 are affected. Users running these builds who visit a malicious website may see the spoofed dialog, which appears legitimate. Starting with build 150.0.7871.47 the UI fix is in place and the vulnerability is removed.
Risk and Exploitability
The CVSS score is 4.3, indicating low severity. The EPSS score is below 1 %, suggesting that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires delivery of a crafted HTML page; attackers cannot execute code or compromise the device beyond stealing credentials entered into the spoofed prompt.
OpenCVE Enrichment
Debian DLA
Debian DSA