Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*
- < 148.0.7778.216
A vulnerability in Google Chrome on iOS, affecting versions prior to 148.0.7778.216, allowed remote attackers to inject arbitrary scripts or HTML, leading to universal cross-site scripting (UXSS). This was achieved by convincing users to perform specific UI gestures on a crafted HTML page.
Exploitation of this vulnerability allowed for universal cross-site scripting, where injected scripts could be executed in the context of the user's browser.
Users can update to Google Chrome version 148.0.7778.216 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.