Impact
The vulnerability is a use‑after‑free flaw in the mobile component of Google Chrome on iOS, allowing the execution of arbitrary code when a user performs specific UI gestures on a crafted HTML page. The flaw requires the attacker to convince the user to interact with a malicious web page that triggers the vulnerability, after which the attacker can run code with the privileges of the browser process.
Affected Systems
Google Chrome for iOS versions earlier than 148.0.7778.96 are affected. The issue is confined to the mobile release of the browser and does not impact other Google Chrome platforms.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. Chromium labels the issue as critical, however no EPSS score is available and the vulnerability is not currently listed in CISA's KEV catalog. The attack requires user interaction with a malicious web page, indicating that exploitation probability depends on successful phishing or social‑engineering techniques. Once achieved, the attacker can acquire full code execution privileges within the browser context.
OpenCVE Enrichment
Debian DSA