Impact
Chrome for iOS displays an incorrect security UI for sites, allowing a remote attacker to craft an HTML page that causes users to see a spoofed warning or dialog. This vulnerability gives attackers the ability to impersonate legitimate security prompts. The primary impact is deception of users into divulging sensitive information or performing unintended actions, undermining confidentiality of user credentials and potentially leading to financial loss or credential compromise.
Affected Systems
The issue affects Google Chrome on iOS devices running any version prior to 151.0.7922.72. Versions 151.0.7922.72 and later contain the fix. Only the iOS builds of Chrome are impacted; other platforms are not affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity. The EPSS score of less than 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, where the attacker hosts a malicious web page that users load, thereby triggering the spoofed UI. Because it requires the user to visit the crafted page, exploitation depends on user interaction rather than a purely technical attack.
OpenCVE Enrichment
Debian DLA
Debian DSA