Impact
A flaw in Google Chrome’s Geolocation component before version 150.0.7871.47 allows a remote attacker to serve a crafted HTML page that triggers a location request, causing the browser to present spoofed geographic information to the user. This vulnerability is categorized as CWE-451 and only misleads the user about their location; it does not provide code execution, privilege escalation, or compromise of system integrity.
Affected Systems
Google Chrome browsers earlier than 150.0.7871.47 are affected. The flaw is present in the geolocation subsystem across all platforms. Updating to Chrome version 150.0.7871.47 or any later patch removes the defect.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1 % points to a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTML page that requests geolocation; an attacker needs the victim to visit the page and grant location permission. Because the flaw only allows UI spoofing, the compromise scope is limited to the user’s perception of location data.
OpenCVE Enrichment
Debian DLA
Debian DSA