Junglewise Threat Intelligence

CVE-2026-13867: Google Chrome UI spoofing in Geolocation

CVE-2026-13867 · Severity: info · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a vulnerability in its Geolocation component. A remote attacker could use a specially crafted website to trick users by spoofing parts of the browser's user interface. This could lead to users being misled about their location settings or other security-sensitive information, potentially facilitating further phishing or social engineering attacks.

Technical details

A UI spoofing vulnerability exists in the Geolocation component of Google Chrome prior to version 150.0.7871.47. The flaw stems from an inappropriate implementation that allows a remote attacker to manipulate or misrepresent user interface elements when a victim visits a malicious HTML page. This is a network-based attack that requires the victim to navigate to a specially crafted site. Successful exploitation could allow an attacker to deceive users regarding the state of their geolocation permissions or other browser UI elements. The issue has been addressed in the stable channel update for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: advisory: Google released a stable channel update addressing the issue.
  • 2026-06-30: patched

References

Related threats