Impact
An inappropriate implementation of the Geolocation component in Google Chrome allows a remote attacker who has already compromised the renderer process to deliver a crafted HTML page that uses the Geolocation API to generate a spoofed user interface as CWE-451. The injected UI can mislead users, potentially causing them to provide credentials or interact with a malicious form, facilitating a phishing attack at the presentation layer.
Affected Systems
The issue is present in Google Chrome desktop releases that precede 150.0.7871.47, meaning any user running earlier versions of the browser is susceptible. It is inferred that only the Geolocation feature is impacted, and the vulnerability does not extend to other Chrome components or third‑party applications relying on the browser.
Risk and Exploitability
Exploitation requires the attacker first compromise the renderer process, a prerequisite indicating the attacker already has some level of control within Chrome. Once that condition is satisfied, the attacker can serve a crafted HTML page that uses the Geolocation API to generate a spoofed user interface. The CVSS score of 6.5 and the EPSS below 1 % suggest a low likelihood of exploitation, and because the vulnerability is not listed in the CISA KEV catalog it is considered lower‑profile. Nevertheless, if a renderer compromise occurs, the risk of phishing and erosion of user trust is moderate to high, as the spoofed UI can deceive users into providing sensitive information.
OpenCVE Enrichment
Debian DLA
Debian DSA