Impact
An improper implementation in Chrome for iOS, before version 151.0.7922.72, permits a remote attacker to deliver a crafted HTML page that causes the browser to display a spoofed user interface. When this spoofing occurs, the user may see a false representation of the browser chrome or web page, possibly affecting interaction with the application.
Affected Systems
Google Chrome for iOS versions older than 151.0.7922.72 are affected. The issue applies solely to the iOS build of Chrome and does not impact newer releases. The official advisory references a stable channel update that addresses the flaw.
Risk and Exploitability
The CVSS score of 4.3 indicates low overall severity, and the EPSS score of <1% shows a very low probability of exploitation. The attack vector is remote and web‑based, requiring an attacker to host or serve a crafted HTML page. The vulnerability is not listed in the CISA KEV catalog, suggesting no known active exploitation. The primary risk is that users may interact with a fraudulent interface that mimics legitimate UI elements.
OpenCVE Enrichment
Debian DLA
Debian DSA