Impact
Chrome for iOS prior to 151.0.7922.72 has insufficient policy enforcement that permits a remote attacker to bypass navigation restrictions by delivering a crafted HTML page. The flaw is exploitable remotely when a user opens such a page and is considered a Medium severity issue by Chromium.
Affected Systems
This vulnerability affects Google Chrome for iOS versions older than 151.0.7922.72. Any device running these releases is susceptible, including iPhones and iPads that have not applied the latest update.
Risk and Exploitability
The EPSS score is <1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires a crafted web page that the user visits, meaning exploitation is possible with standard web access. While the severity rating is Medium, there is no known active exploitation. Organizations should consider the potential impact within their threat model.
OpenCVE Enrichment
Debian DLA
Debian DSA