Impact
An inappropriate implementation in Chrome for iOS allowed a remote attacker to potentially escape the web sandbox through a crafted HTML page. This flaw corresponds to CWE-693 and could enable the attacker to execute code outside the browser context, compromising the device's confidentiality, integrity, and availability. The vulnerability has a CVSS score of 9.6, indicating high severity.
Affected Systems
Affected products are Google Chrome for iOS before version 151.0.7922.72. Any device running that version of the Chrome app is potentially vulnerable until the update is installed.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited evidence of widespread exploitation. Nevertheless, the high CVSS score and the remote nature of the attack imply that a crafted malicious webpage could trigger the sandbox escape from a remote site, giving an attacker privileged code execution. Following the advisory, users should apply the update as soon as it becomes available to mitigate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA