Impact
A use‑after‑free flaw exists in Chrome for iOS that can corrupt the heap when a crafted HTML page is loaded. The corruption could allow a remote attacker to execute arbitrary code or otherwise compromise the device. The weakness is identified as CWE‑416 and the reported CVSS score of 8.8 indicates significant potential impact, although the official severity is listed as low. No confirmed exploits are currently known, but the possibility of misuse remains.
Affected Systems
Google Chrome for iOS versions prior to 151.0.7922.72.
Risk and Exploitability
The CVSS score of 8.8 reflects a high impact, with a low EPSS (<1%) and no listing in the CISA KEV catalog. The flaw is a use‑after‑free that requires the attacker to deliver a crafted HTML page to a user; no confirmed exploits are known, so current risk is considered low to moderate.
OpenCVE Enrichment
Debian DLA
Debian DSA