Impact
This vulnerability is a use‑after‑free flaw in the Mobile version of Google Chrome for iOS. The defect permits a remote attacker, by sending specially crafted network traffic, to execute arbitrary code outside the browser sandbox. The impact is compromise of the device’s integrity and potential leakage of user data. It is classified as a high‑severity issue due to the breadth of damage the attacker can cause.
Affected Systems
The affected product is Google Chrome on iOS, specifically versions prior to 152.0.7977.65. Users running these versions are vulnerable to remote code execution when parsing network requests.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1 and an EPSS score of <1%, and it is not listed in the CISA KEV catalog. It can be exploited remotely over the network by sending crafted traffic that triggers the freed memory usage, causing arbitrary code to execute with Chrome privileges and potentially escape the sandbox. Despite the low EPSS score, the potential damage warrants precaution.
OpenCVE Enrichment
Debian DLA
Debian DSA