Impact
In Google Chrome for iOS versions earlier than 151.0.7922.72, a flaw allows a remote attacker to manipulate the text displayed in the Omnibox, the URL bar, by delivering a specially crafted HTML page. This issue is a user‑interface spoofing vulnerability classified as CWE-451, leading users to see an incorrect website name or address while interacting with the browser.
Affected Systems
Affected by this vulnerability are users of Google Chrome for iOS running versions prior to 151.0.7922.72.
Risk and Exploitability
The CVSS score of 4.3 reflects a moderate risk, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The flaw is not currently listed in the CISA KEV catalog. Attackers would typically lure a user to a malicious web page that triggers the spoofing behavior, making a direct network‑based attack unnecessary. The recommended course of action is to update Chrome to 151.0.7922.72 or later.
OpenCVE Enrichment
Debian DLA
Debian DSA