Sceawere

Vulnerability Detail

CVE-2026-79075UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Chrome Geolocation Information Leak

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
1d ago
Vendor
Google
Product
Chrome
Attack Type
Information leak
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Information leak in Geolocation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: Medium)

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-25T21:18:03.280Z",
  "pubdate": "2026-08-25T21:18:03.280Z",
  "executiveSummary": "A security vulnerability categorized as an information disclosure issue exists within the Geolocation functionality of Google Chrome prior to version 152.0.7977.65. The flaw permits a remote attacker to circumvent privacy controls and exfiltrate sensitive location data from a user's device. This vulnerability is classified as Medium severity by the Chromium project. Successful exploitation requires the attacker to employ social engineering techniques to induce a user into interacting with a specifically crafted HTML page. Once triggered, the vulnerability allows unauthorized access to geolocation metadata, posing a significant risk to user privacy and physical security. The attack does not necessarily require high-level system privileges, but relies on the target's interaction with malicious web content to initiate the unauthorized data acquisition flow.",
  "technicalDetails": "The vulnerability resides in the Geolocation implementation within the Chromium browser engine, specifically concerning how the browser validates and authorizes location requests originating from web content. The root cause pertains to an improper check or state management within the permissions handling subsystem, which governs the Geolocation API access. Under normal operation, the Geolocation API requires an explicit, user-initiated permission prompt before a web page can query the device's latitude, longitude, and altitude data.\nThe exploitation process involves an attacker hosting a crafted HTML document designed to manipulate the browser's expectation of user intent. By leveraging social engineering—such as misleading prompts, deceptive UI overlays, or tricking the user into enabling a context that the browser incorrectly validates—the attacker can influence the browser to trigger a Geolocation request without fulfilling the standard security requirements or explicit user consent. Because the browser fails to properly isolate or verify the source and context of the request, the underlying API mechanism proceeds to expose sensitive coordinates to the attacker-controlled script.\nThe attack flow begins when a user navigates to the malicious page. The page executes JavaScript designed to invoke the Geolocation API. Through the identified logic flaw, the browser's security boundary is bypassed, allowing the API to return the device's geolocation coordinates to the attacker's server via an asynchronous request (e.g., fetch or XMLHttpRequest).\nThis vulnerability affects all Google Chrome versions prior to 152.0.7977.65. There is no requirement for the attacker to possess authenticated access or local system privileges; the exploit is purely client-side, executed within the browser's sandboxed environment but leveraging a flaw in the browser's own permission management logic. The post-exploitation impact includes the systematic tracking of the user's physical movements and potential correlation with other deanonymization vectors, leading to significant privacy violations."
}
CVE-2026-79075: Chrome Geolocation Information Leak (MEDIUM Severity, CVSS: 6.5) - Sceawere