Impact
An insufficient validation of untrusted input in Chrome for iOS allows a remote attacker to bypass navigation restrictions via malicious network traffic. This flaw enables the attacker to force the browser to navigate to arbitrary URLs, potentially compromising the user’s intent and facilitating unauthorized content delivery.
Affected Systems
Google Chrome for iOS versions older than 151.0.7922.72 are affected. Users on earlier builds of the Chrome browser for iOS devices are at risk until they install the patched release.
Risk and Exploitability
The EPSS score is below 1 % and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of widespread exploitation at this time. The Chromium security severity is Medium, suggesting that while the impact is limited to navigation control, it can be leveraged remotely by delivering malformed network traffic to the device. Successful exploitation would result in the browser overriding its navigation restrictions to access unintended URLs.
OpenCVE Enrichment
Debian DLA
Debian DSA