Impact
An incorrect display of the security UI in Chrome for iOS before version 151.0.7922.72 lets a remote attacker craft a malicious HTML page that causes the browser to show a falsified domain name to the user. The flaw is a type‑safety violation (CWE‑451) that results in user deception, potentially leading to phishing or credential theft rather than direct code execution.
Affected Systems
Google Chrome for iOS versions earlier than 151.0.7922.72 are affected; only the iOS build of Chrome is vulnerable, other operating system versions are not impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1 % and the absence from CISA’s KEV catalog imply a low current exploitation probability. The likely attack vector is a user visiting a malicious page in Chrome for iOS; no special privileges are required and the impact is limited to deception and possible credential compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA