Impact
The vulnerability is a use‑of‑uninitialized‑variable flaw in the Mobile component of Google Chrome on iOS, affecting releases older than 152.0.7977.65. A crafted HTML page can cause the variable to contain unpredictable data, potentially allowing an attacker to execute arbitrary code outside the Chrome sandbox. The flaw falls under CWE‑457 and is rated as critical by Chromium security teams.
Affected Systems
Affected systems are devices running Google Chrome for iOS prior to version 152.0.7977.65.
Risk and Exploitability
Exploitability is high because it requires only a remote attacker to load a malicious web page, which is a typical browsing scenario. The EPSS score is <1%, and the CVSS score of 9.6 indicates a severe risk. The vulnerability is not listed in the CISA KEV catalog, yet the potential for arbitrary code execution warrants immediate remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA