Impact
This vulnerability involves an observable discrepancy in the Safebrowsing service of Google Chrome on iOS. An attacker who can compromise the renderer process could serve a specially crafted HTML page that would lead to the disclosure of sensitive data. The flaw is categorized as a default-data-encapsulation error, as identified by CWE‑203, and is rated as medium severity by Chromium. Importantly, the vulnerability does not allow arbitrary code execution or direct destruction of services, but it does expose information that can be leveraged for further attacks or credential theft.
Affected Systems
The flaw is present in Chrome for iOS versions earlier than 153.0.8010.36. Users running any older stable channel build on iOS devices are vulnerable. No other platforms or plugins are listed as affected.
Risk and Exploitability
Because the flaw requires the attacker to first compromise the renderer process, the attack vector is more limited than a remote code execution path; however, once the renderer is compromised, sensitive data can be exfiltrated via a crafted web page. Although the EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, the medium severity rating and the potential impact on confidentiality warrant prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA