Impact
A race condition in Google Chrome’s mobile iOS implementation allows a remote attacker to bypass the browser’s web origin policy when a specially crafted HTML page is served. The flaw requires the victim to be social‑engineered into opening the malicious page, after which the attacker can read or manipulate content from a different origin without the usual same‑origin restrictions. This can enable cross‑origin data theft, manipulation of web pages, and potentially privilege escalation if combined with other browser features.
Affected Systems
The vulnerability affects Google Chrome Mobile on iOS versions prior to 153.0.8010.36. Versions 153.0.8010.36 and later include the fix and are not susceptible.
Risk and Exploitability
Because the flaw is low‑severity (CVSS 3.1) and relies on user interaction with a malicious web page, the EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via browser, requiring social engineering to get the victim to load the crafted content. If exploited, the attacker can bypass origin restrictions, potentially leading to data exfiltration or unauthorized script execution.
OpenCVE Enrichment
Debian DLA
Debian DSA