Impact
Google Chrome on iOS suffers a use‑after‑free flaw in the Sync component that allows a remote attacker to supply a crafted HTML page and potentially execute code outside the browser sandbox. The flaw is a classic memory management bug (CWE‑416) and can lead to full device compromise if executed successfully. The description emphasizes that the impact is limited to code execution but carries significant severity in terms of confidentiality, integrity, and availability of the affected device.
Affected Systems
All users of Google Chrome on iOS with a build prior to 152.0.7977.65 are affected. The bug was present in the Sync feature of the browser and does not apply to non‑iOS platforms or later releases.
Risk and Exploitability
The CVSS score is not provided and the EPSS score is unavailable, but the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a crafted web page delivered over HTTP/HTTPS. Because the flaw allows execution outside the sandbox, it is a high‑impact vulnerability, yet the overall risk is tempered by the lack of widespread exploitation evidence at this time.
OpenCVE Enrichment