Impact
This vulnerability allows a remote attacker to transmit sensitive data in cleartext through the HttpsUpgrades feature of Google Chrome on iOS. The weakness is classified as CWE-319, which encryption. An attacker who can feed crafted network traffic to a vulnerable device could capture and read the data that the browser transmits, leading to exposure of confidential information.
Affected Systems
Google Chrome on iOS versions prior to 153.0.8010.36 is affected. The issue was identified in the stable channel and was addressed in the 153.0.8010.36 release.
Risk and Exploitability
The vulnerability is rated as Medium severity, with a CVSS score of 5.9, by Chromium. It is not listed in the CISA KEV catalog and its EPSS score is less than 1%. Because exploitation requires the attacker to send malicious traffic to a vulnerable device running a vulnerable Chrome version, the attack vector is network-based. While the risk remains moderate, the potential loss of sensitive data warrants immediate remediation if a patch is not applied.
OpenCVE Enrichment
Debian DLA
Debian DSA