Impact
The vulnerability is a race condition (CWE-362) that permits a remote attacker to perform UI spoofing in Google Chrome on iOS. By serving a specially crafted HTML page, an attacker may cause the browser to render interface elements incorrectly, letting them trick users into interacting with deceptive buttons or fields. The impact includes user confusion, potential credential or data leakage, and a compromised user experience.
Affected Systems
Affects Google Chrome on iOS prior to version 151.0.7922.72. No other vendors or product versions are listed, so the vulnerability is confined to this specific Chrome build on Apple devices.
Risk and Exploitability
The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low likelihood of current exploitation. The Chromium security severity is Medium, suggesting a moderate risk. The attack vector appears to be remote via a crafted web page, with the attacker needing to lure a user to open the malicious content on affected devices. Since no active exploits have been reported, the risk remains theoretical but a patch is strongly recommended.
OpenCVE Enrichment
Debian DLA
Debian DSA