Impact
In Google Chrome on iOS, an improper handling of media data allowed a remote attacker who had already taken over the renderer process to read data outside of allocated memory when loading a crafted HTML page. The vulnerability is a classic out‑of‑bounds read, classified as CWE‑693. The potential impact is information disclosure from the attacker’s perspective, with no confirmed escalation to higher privileges or code execution. Chrome’s own security team rates the severity as Medium, indicating a notable but limited risk if the preconditions are met.
Affected Systems
Chrome for iOS versions prior to 148.0.7778.168 are affected. No additional vendor or product information is listed.
Risk and Exploitability
Exploitation requires the attacker to have already compromised the renderer process, a serious prerequisite that limits the attack surface. Because the EPSS score is < 1%, the likelihood of widespread exploitation is uncertain, and the vulnerability is not yet listed in the CISA KEV catalog. The CVSS score of 7.5 and the medium Chromium security rating suggest that while the flaw is not trivially exploitable, it should be treated with caution, especially in environments where renderer processes could be exposed to untrusted content.
OpenCVE Enrichment
Debian DSA