Impact
A flaw in Chrome for iOS allows a remote attacker to craft a malicious HTML page that can impersonate legitimate application UI, misleading users into performing unintended actions. The vulnerability, classified as CWE‑451, is considered low severity, with a CVSS score of 4.3. The CVE description does not explicitly state the exact mechanism of exploitation, but it is inferred that a crafted HTML page is involved.
Affected Systems
All iOS installations of Google Chrome running a version earlier than 151.0.7922.72 are affected. No other platforms or product variants are impacted. This platform and version specificity is inferred from the product list and description; the CVE data does not explicitly enumerate platform versions.
Risk and Exploitability
The CVSS rating reflects low overall damage potential, and the EPSS score of less than 1% indicates that active exploitation is unlikely at this time. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the victim to open a crafted HTML page, which a malicious actor could deliver through a compromised website or email link. No credential theft or privilege escalation is involved; the threat is limited to UI manipulation. The CVE data does not explicitly detail the exploit prerequisites; this inference is based on the description.
OpenCVE Enrichment
Debian DLA
Debian DSA