Impact
The flaw arises from insufficient policy enforcement in Chrome for iOS, allowing an attacker to engineer a crafted HTML page that causes the browser to navigate to restricted URLs. This is a classic insufficient authorization weakness (CWE‑602) that could lead to unauthorized browsing and access to content blocked by corporate or parental controls.
Affected Systems
Google Chrome on iOS versions older than 151.0.7922.72 are affected. Users of the stable channel prior to this build that have not upgraded are at risk.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact, while the EPSS score of less than 1% suggests the likelihood of real‑world exploitation is low. It is not listed in the CISA KEV catalog, and the attack vector is remote, requiring the victim to load a malicious page on a device that has the vulnerable browser installed. No additional conditions are required beyond user interaction.
OpenCVE Enrichment
Debian DLA
Debian DSA