page/Geolocation.cpp in WebCore in WebKit before r56188 and before 1.2.5 does not properly restrict access to the lastPosition function, which has unspecified impact and remote attack vectors, aka rdar problem 7746357.
https://bugs.webkit.org/show_bug.cgi?id=36255
http://www.vupen.com/english/advisories/2011/0552
http://www.vupen.com/english/advisories/2011/0212
http://www.vupen.com/english/advisories/2010/2722
http://www.ubuntu.com/usn/USN-1006-1
http://www.securityfocus.com/bid/42500
http://www.mandriva.com/security/advisories?name=MDVSA-2011:039
http://trac.webkit.org/changeset/56188
http://security-tracker.debian.org/tracker/CVE-2010-1386
http://secunia.com/advisories/43068
http://secunia.com/advisories/41856
http://lists.opensuse.org/opensuse-security-announce/2011-01/msg00006.html