Impact
The vulnerability originates from an inappropriate implementation in Chrome for iOS that enables UI spoofing when a malicious webpage is rendered. Attackers can create a crafted HTML page that tricks users into interacting with deceptive interface elements. This flaw poses a phishing risk but does not allow execution of code or privileged operations. Based on the description, the attack vector is a malicious Web page loaded in the browser. The weakness aligns with CWE-451.
Affected Systems
Google Chrome on iOS versions prior to 151.0.7922.72. Users running any older mobile Chrome build are vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. The EPSS score is below 1% and the flaw is not in the KEV catalog, indicating a low likelihood of active exploitation at this time. Security teams should note the limited attack surface: a threat actor must host a malicious web page that a user visits and interacts with. While rare, the impact includes credential theft or misleading user actions. Upgrading to the fixed version provides the only documented solution.
OpenCVE Enrichment
Debian DLA
Debian DSA