Description
Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome’s Geolocation component before version 150.0.7871.47 allows a remote attacker to serve a crafted HTML page that triggers a location request, causing the browser to present spoofed geographic information to the user. This vulnerability is categorized as CWE-451 and only misleads the user about their location; it does not provide code execution, privilege escalation, or compromise of system integrity.

Affected Systems

Google Chrome browsers earlier than 150.0.7871.47 are affected. The flaw is present in the geolocation subsystem across all platforms. Updating to Chrome version 150.0.7871.47 or any later patch removes the defect.

Risk and Exploitability

The CVSS score of 4.3 indicates medium severity, while the EPSS score of less than 1 % points to a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a crafted HTML page that requests geolocation; an attacker needs the victim to visit the page and grant location permission. Because the flaw only allows UI spoofing, the compromise scope is limited to the user’s perception of location data.

Generated by OpenCVE AI on July 16, 2026 at 12:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer to apply the vendor patch.
  • If immediate upgrade is not possible, disable or restrict geolocation permission for sites that do not require location access, limiting the browser’s ability to provide possibly spoofed data.
  • Implement automatic update policies or enforce enterprise update procedures to ensure Chrome stays on the latest secure release.

Generated by OpenCVE AI on July 16, 2026 at 12:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing in Google Chrome

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing in Google Chrome

Sun, 12 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing Vulnerability in Google Chrome

Fri, 10 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing Vulnerability in Google Chrome

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome Geolocation UI Spoofing via Crafted HTML Page

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Geolocation UI Spoofing via Crafted HTML Page

Tue, 07 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing in Google Chrome Prior to 150.0.7871.47

Mon, 06 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing in Google Chrome Prior to 150.0.7871.47

Sun, 05 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Chrome Geolocation UI Spoofing Vulnerability

Sat, 04 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Chrome Geolocation UI Spoofing Vulnerability

Sat, 04 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Google Chrome Geolocation Feature Vulnerable to UI Spoofing via Crafted Web Pages

Fri, 03 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Google Chrome Geolocation Feature Vulnerable to UI Spoofing via Crafted Web Pages

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Geolocation in Google Chrome

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Remote UI Spoofing via Geolocation in Google Chrome

Thu, 02 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Geolocation‑Based UI Spoofing in Google Chrome

Wed, 01 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Geolocation‑Based UI Spoofing in Google Chrome

Wed, 01 Jul 2026 18:15:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing Vulnerability in Google Chrome
Weaknesses CWE-1021
CWE-1181

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Geolocation UI Spoofing Vulnerability in Google Chrome
Weaknesses CWE-1021
CWE-1181

Wed, 01 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T14:05:50.313Z

Reserved: 2026-06-29T23:03:37.649Z

Link: CVE-2026-13867

cve-icon Vulnrichment

Updated: 2026-07-01T14:05:16.719Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:45:05Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information