Impact
The flaw involves insufficient policy enforcement in Chrome for iOS, allowing a remote attacker to supply a crafted HTML page that the victim renders. When the page loads, the browser fails to enforce its discretionary access controls, letting the attacker access data or browser state that should have been restricted. This can compromise personal information or enable further malicious actions if the user interacts with the page.
Affected Systems
The vulnerability affects Google Chrome for iOS versions before 151.0.7922.72. No other vendors or products are listed in the CNA data for this issue.
Risk and Exploitability
The CVSS score of 6.5 identifies a medium severity flaw, while the EPSS score below 1% indicates a low exploitation probability at present. The issue is not included in the CISA KEV catalog. Based on the description, it can be inferred that a remote attacker could exploit the flaw by hosting a malicious web page that the victim visits, thereby bypassing the browser’s discretionary access restrictions.
OpenCVE Enrichment
Debian DLA
Debian DSA