Impact
An improper implementation in Chrome for iOS allows a remote attacker to craft an HTML page that can spoof the user interface. By displaying deceptive UI elements, an attacker may trick the user into interacting with fake prompts or buttons, and while the CVE description does not explicitly state a direct credential exposure outcome, it is inferred that such exposure could occur based on the nature of UI spoofing. This weakness is identified as CWE‑451.
Affected Systems
Google Chrome for iOS versions earlier than 151.0.7922.72 are affected. The vulnerability is limited to the iOS platform and does not impact desktop or Android versions of Chrome.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1 percent shows a very low likelihood of exploitation in the wild. The vulnerability is not listed in CISA KEV, suggesting it has not been identified as a widely exploited risk. Exploitation requires a malicious web page or content that a user visits; thus, it is an attack that needs user interaction and is constrained to the local application context.
OpenCVE Enrichment
Debian DLA
Debian DSA