Impact
A local attacker can cause an information leak by delivering a specially crafted file that is opened by Google Chrome on iOS versions before 152.0.7977.65. The vulnerability, classified as CWE-200, allows the attacker to read sensitive information that should not be exposed through the browser’s handling of that file. Because the flaw is limited to local access and has been deemed of low severity by Chromium’s assessment, the impact is primarily a privacy violation rather than a compromise of system integrity or availability.
Affected Systems
The affected product is Google Chrome for iOS, specifically all releases prior to version 152.0.7977.65. Users running those older releases on iOS devices are susceptible to the leak if they receive or open crafted files.
Risk and Exploitability
Detailed exploitation likelihood is not quantified in the EPSS database and the vulnerability is not listed in the CISA KEV catalog, indicating the current risk exposure is modest. The attack vector requires local access or the ability to supply a malicious file to the device, which in practice limits the potential for widespread exploitation. No public zero-day exploits have been reported, but the flaw still warrants a remedial action to prevent private data leakage.
OpenCVE Enrichment