Impact
An inappropriate implementation in Chrome for iOS allowed a remote attacker, by convincing a user to perform specific UI gestures, to leak cross‑origin data through a crafted HTML page. The flaw is a broken access control weakness (CWE‑346) that results in information disclosure rather than execution of arbitrary code or denial of service.
Affected Systems
The vulnerability affects Google Chrome for iOS, specifically any version prior to 151.0.7922.72. No alternative vendors or products are listed.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% reflects a very low but non‑zero likelihood of exploitation. The vulnerability is not present in the CISA KEV catalog. Exploitation requires user interaction—an attacker must first lure the user to a crafted page and force specific gestures—making the attack vector phishing or social‑engineering rather than a purely remote or network‑based vector.
OpenCVE Enrichment
Debian DLA
Debian DSA