Impact
The vulnerability resides in Chrome for iOS prior to version 151.0.7922.72. A malicious web page can lure a user into performing a specific sequence of UI gestures, such as swipes or taps, that the browser processes incorrectly. This defect allows the attacker to bypass the same‑origin policy and read data or perform actions that would normally be restricted to a different origin, potentially exposing confidential information or enabling unauthorized actions on behalf of the user. The flaw is an implementation error that undermines the browser’s security boundary. This is a classic example of an access control weakness, which is reflected in the associated CWE identifiers.
Affected Systems
Google Chrome for iOS versions older than 151.0.7922.72 are affected. iPhone and iPad users running the stable channel of Chrome before that release are vulnerable if they visit a malicious site that instructs them to perform the required gestures.
Risk and Exploitability
Chromium classifies the weakness as a medium‑severity issue, with a CVSS score of 6.5. The EPSS score is less than 1%, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Attackers must convincingly persuade a user to execute a specific gesture sequence on a malicious page, making large‑scale automated exploitation unlikely. Nevertheless, the ability to read cross‑origin data presents a significant confidentiality risk, and any user who performs the gesture sequence on a compromised site becomes a vector for data theft or unauthorized operations.
OpenCVE Enrichment
Debian DLA
Debian DSA