Impact
Improper input validation in the Mobile component of Google Chrome on iOS before version 152.0.7977.65 enabled a remote attacker to bypass system access restrictions by serving a crafted HTML. The flaw could be leveraged to gain unauthorized system privileges through a web‑based attack vector. The weakness is identified as CWE-20, reflecting an input validation error.
Affected Systems
Google Chrome for iOS users whose browsers run versions earlier than 152.0.7977.65. All devices using the affected Chrome builds are at risk.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3, an EPSS of <1%, and is not listed in the CISA KEV catalog. Based on the description, the attacker must be able to deliver a crafted HTML page to the target iOS device, suggesting a remote exploitation path that requires user interaction or a malicious webpage. While the lack of severity metrics makes precise risk quantification difficult, the widespread use of Chrome on iOS and the remote nature of the attack raise concerns about potential impact.
OpenCVE Enrichment
Debian DLA
Debian DSA