Impact
A flaw in Google Chrome’s Geolocation component before version 150.0.7871.47 allows a remote attacker to deliver a crafted HTML page that triggers a location request, causing the browser to display user‑facing location information that has been spoofed. The vulnerability is identified as CWE-451, reflecting improper handling of user‑controlled data. The impact is the deliberate misrepresentation of geographic data to the user; it does not lead to code execution, privilege escalation, or compromise of system integrity.
Affected Systems
Google Chrome browsers earlier than version 150.0.7871.47 on all operating systems are affected. The issue resides in the geolocation subsystem and is present across all platforms where Chrome runs.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1 % signals a very low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a crafted HTML page that requests geolocation; the attacker requires the victim to visit the page and grant location permission. Because the flaw only leads to UI spoofing, the compromise scope is confined to the user’s perception of their location.
OpenCVE Enrichment
Debian DLA
Debian DSA