Impact
A failed validation of input data in the Transactions Platform component of Google Chrome on iOS permits a remote attacker to deliver a crafted HTML page that can cause the browser to execute code outside its sandbox. The flaw is rooted in an input validation weakness and is classified as CWE‑20. This could allow an attacker to run arbitrarily complex code on the user’s device, potentially compromising data confidentiality, integrity, and availability.
Affected Systems
All Google Chrome installations on iOS devices running a version prior to 152.0.7977.82 are affected. The vulnerability is tied to the Transactions Platform component inherent to Chrome’s rendering engine on iOS.
Risk and Exploitability
Because the flaw allows code execution beyond the browser’s sandbox, the impact is severe. The CVSS score of 9.6 further emphasizes the high severity. The attack requires presenting a malicious HTML page to a user who then browses it. No public exploitation evidence or EPSS score is available, and the vulnerability is not listed in CISA’s KEV catalog, suggesting limited or no active exploitation at this time. Nonetheless, the potential for arbitrary code execution means the risk remains high for users who may encounter malicious content.
OpenCVE Enrichment
Debian DLA
Debian DSA