Impact
The vulnerability in Google Chrome for iOS, affecting builds prior to 150.0.7871.47, allows a malicious web page to display a counterfeit password prompt that looks like the legitimate dialog. When a user enters credentials into that spoofed prompt, the attacker can capture the login information. The weakness is classified as CWE‑451. No arbitrary code execution or system compromise can be achieved; the flaw solely permits deception and credential leakage.
Affected Systems
Chrome for iOS versions before 150.0.7871.47 are affected. Users who visit a malicious website that serves the crafted HTML page may be presented with the spoofed dialog and potentially provide their credentials.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity. The EPSS score is below 1 %, suggesting exploitation is unlikely at present. The vulnerability has not been listed in the CISA KEV catalog. Exploitation requires a user to open a malicious web page; there is no code execution or device compromise beyond stolen credentials.
OpenCVE Enrichment
Debian DLA
Debian DSA