Impact
Insufficient validation of untrusted input in Chrome for iOS prior to 151.0.7922.72 permits a remote attacker to bypass navigation restrictions via a crafted HTML page. This flaw allows the attacker to direct the browser to any URL that is normally blocked, potentially compromising the user’s security context and privacy. The weakness is an input validation failure (CWE‑20).
Affected Systems
Google Chrome on iOS versions earlier than 151.0.7922.72 are impacted. All devices running those releases are susceptible until they update to the fixed build.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1 %, implying a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a crafted web page delivered to the user, possibly from a malicious site. Attackers could target users through phishing or compromised sites, but widespread, automated exploitation is currently unlikely.
OpenCVE Enrichment
Debian DLA
Debian DSA