Impact
The vulnerability stems from insufficient policy enforcement in Chrome for iOS, allowing a remote attacker to perform UI spoofing through a crafted HTML page. The attacker could potentially deceive users into interacting with a counterfeit interface, thereby enabling social engineering attacks. This weakness is categorized as CWE-346, indicating a code injection or compromise via improperly enforced authorization checks.
Affected Systems
Google Chrome on iOS versions prior to 151.0.7922.72 are affected. No other vendors or products were listed as impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity level, and the EPSS score is noted as less than 1%, suggesting a very low likelihood of exploitation at this time. The vulnerability is not present in the CISA KEV catalog. Based on the description, a remote attacker could exploit the flaw by delivering the malicious HTML page, likely through a compromised or deceptive website accessed on a vulnerable Chrome for iOS installation.
OpenCVE Enrichment
Debian DLA
Debian DSA