Impact
A confused deputy flaw in Google Chrome’s PriceTracking component on iOS allows a remote attacker to craft network traffic that misleads the browser into granting access to a privileged page. The flaw bypasses normal system access restrictions, enabling the attacker to view or modify content from a page that should be protected. This constitutes an unauthorized escalation of privileges and could expose sensitive information or allow further manipulation of the application.
Affected Systems
The vulnerability affects versions of Google Chrome for iOS on the stable channel prior to 153.0.8010.47. Any device running an impacted iOS version of Chrome could be susceptible. The vulnerability is specific to the PriceTracking feature within the browser.
Risk and Exploitability
The CVSS base score is rated Medium in Chromium’s assessment, and the EPSS score is below 1%, indicating a low overall probability of exploitation at the moment. The vulnerability is not recorded in CISA’s KEV catalog. Attackers would typically need to combine a social engineering attempt with crafted traffic to exploit the confused deputy, which suggests the required steps are nontrivial but feasible for a skilled adversary. Should the flaw be leveraged, the adversary could bypass access controls and gain entry to privileged browser pages.
OpenCVE Enrichment