Impact
A race condition in Chrome for iOS before version 151.0.7922.72 lets a remote attacker craft an HTML page that causes the browser to execute arbitrary scripts or HTML. This can result in the execution of code within the browser context, potentially compromising the integrity of the browsing session. The weakness is identified as a race condition (CWE-362) and is rated Chromium severity high.
Affected Systems
Google Chrome for iOS, versions preceding 151.0.7922.72. The vulnerability exists in any Chrome iOS build prior to this update. Users of iOS devices running older Chrome installations are at risk.
Risk and Exploitability
The EPSS score of less than 1 % indicates a low probability of automated exploitation at present, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.2 reflects medium severity. Exploitation requires a user to open a maliciously crafted page in Chrome for iOS, indicating a remote attack vector that relies on social engineering or phishing. If exploited, the capability to run code within the browser could compromise session integrity and privacy. The overall risk is moderate, but the potential damage warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA