Impact
A crafted HTML page can trigger a geolocation request in Google Chrome versions earlier than 152.0.7977.65, causing the browser to expose sensitive location data to the page. The vulnerability permits a remote attacker, using social engineering techniques, to retrieve confidential user information. The primary weaknesses are information disclosure (CWE‑200) and an input validation issue (CWE‑201).
Affected Systems
Any installation of Google Chrome before version 152.0.7977.65 is vulnerable. The issue applies across the stable channel and older releases that have not received the patch issued on August 2026.
Risk and Exploitability
The exploit requires a user to visit a malicious page and conflate a social‑engineering prompt, so it is a remote but user‑interaction dependent attack. EPSS score is < 1% and the Chromium reported severity is medium and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is 6.5, indicating medium severity. Consequently, the risk remains moderate, yet the potential for data leakage warrants immediate attention.
OpenCVE Enrichment
Debian DLA
Debian DSA