Impact
A bug in Chrome for iOS before 151.0.7922.72 allows a remote attacker to bypass navigation restrictions by delivering a specially crafted HTML page. The flaw is an instance of CWE-284: Improper Access Control. The vulnerability is classified as medium severity by Chromium.
Affected Systems
Google Chrome for iOS devices running any version earlier than 151.0.7922.72. No other vendors or products are affected.
Risk and Exploitability
The EPSS score is reported as less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low likelihood of exploitation. The CVSS score of 6.5 categorizes the vulnerability as medium severity, consistent with Chromium’s classification. The only impact known is a navigation bypass. The attack path, inferred from the description, likely involves a remote host that serves a crafted HTML page to a victim on an iOS device; however, the precise attack vector is not explicitly documented. Potential phishing remains a concern.
OpenCVE Enrichment
Debian DLA
Debian DSA