Impact
An incorrect authorization check in Chrome Mobile on iOS versions before 152.0.7977.65 allows a remote attacker to load a specially crafted HTML page that bypasses a system access restriction. This vulnerability can grant the attacker elevated local privileges or allow access to normally protected resources, violating confidentiality and integrity. The weakness is identified as an authorization flaw (CWE-863).
Affected Systems
Google Chrome for iOS versions earlier than 152.0.7977.65 are affected. The vulnerability applies to all devices running those versions of the Chrome Mobile app on iOS.
Risk and Exploitability
The Chromium security team rates the severity as Medium with a CVSS score of 4.3, and the issue is not yet listed in the CISA KEV catalog. The EPSS score of < 1% indicates a very low but non‑zero exploitation probability. The vulnerability is reachable via a remote crafted webpage, and organizations using affected Chrome iOS versions face a moderate risk of unauthorized access if users visit malicious or unsuspected sites.
OpenCVE Enrichment
Debian DLA
Debian DSA