Executive brief
Google Chrome's Geolocation feature contains a vulnerability that allows attackers to extract sensitive location data through a crafted webpage. An attacker could exploit this via social engineering to trick users into visiting a malicious page, potentially compromising user privacy and revealing physical location information.
Technical details
This is an information disclosure vulnerability in Chrome's Geolocation component. The vulnerability allows a remote attacker to obtain sensitive geolocation data through a crafted HTML page, requiring user interaction (social engineering) as a precondition. The attack vector is network-based and leverages the browser's geolocation API exposure. The vulnerability was fixed in Chrome 152.0.7977.65, released on August 25, 2026. Users on versions prior to 152.0.7977.65 are affected.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65