An iOS WebKit page can make a geolocation prompt name one origin while another receives the location.
WebKit geolocation permission UI in WKWebView and the built-in iOS geolocation provider.
A controlled page requests geolocation and starts a cross-origin navigation while its document remains active. WebKit derives the prompt's displayed origin from the provisional destination rather than the requesting document.
Detail and 2 sources
If the user trusts that label and grants permission, the original document receives the result. The upstream commit documents the condition and adds regression tests, but the supplied evidence does not establish a public exploit or settle patch status.