Impact
Information leak in Google Chrome on iOS prior to 152.0.7977.65 let a local attacker obtain sensitive data by manipulating a crafted file. The vulnerability is classified as low severity and allows the adversary to read stored password information stored on the device.
Affected Systems
Google Chrome for iOS versions earlier than 152.0.7977.65 are affected. Any device running one of those builds could potentially expose user credentials if an attacker can place a crafted file on the system.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, which, combined with a CVSS score of 6.5, suggests a low exploitation potential. The attack vector requires local access and the attacker to construct and deliver a malicious file to the victim’s device. While the impact is limited to local credential disclosure, the privacy implications for users warrant immediate remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA