Impact
The vulnerability in Google Chrome versions earlier than 152.0.7977.65 allows a malicious web page to trigger a geolocation request that causes the browser to expose the user’s precise location data to the page. This information leak occurs due to insufficient permission checks and improper input handling, mapping to CWE‑200 (Information Exposure) and CWE‑201 (Improper Input Validation). An attacker can obtain sensitive user location information using social‑engineering prompts and a crafted HTML page, compromising confidentiality.
Affected Systems
Google Chrome installations prior to version 152.0.7977.65 are affected, across all stable channel releases and any older releases that have not received the August 2026 patch.
Risk and Exploitability
The exploit requires a user to visit a malicious or deceptively legitimate page and respond to a geolocation request prompt, making it a remote but user‑interaction‑dependent attack. With an EPSS score of < 1%, the likelihood of exploitation is low, and the vulnerability is not included in CISA’s KEV catalog. The CVSS score of 6.5 indicates medium severity; nevertheless, the potential for leakage of location data warrants timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA