Impact
A crafted HTML page can trigger an information leak in iOS Google Chrome Mobile versions prior to 153.0.8010.36 when a remote attacker uses social engineering. The vulnerability allows the attacker to read sensitive data that the browser has accessed, potentially including cookies, cached credentials, or other private content. The weakness is a classic information‑disclosure flaw, classified as CWE‑200.
Affected Systems
Google Chrome Mobile for iOS devices running any version before 153.0.8010.36 are affected. Users on newer releases are not impacted.
Risk and Exploitability
The vulnerability can be exploited remotely through a web page the victim visits after being deceived by a social‑engineering trick. No public exploit is listed and the EPSS score is < 1%, indicating a very low probability of a large‑scale attack. The CVSS score of 6.5 reflects a moderate severity, and the vulnerability is not present in the CISA KEV catalog and has a Chromium severity of Low. Nonetheless, users who are likely to click malicious links should apply the fix promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA