logo

Chrome Gemini Vulnerability Lets Attackers Access Victims’ Camera and Microphone Remotely

ID: 03043d7a-5036-5dfa-bab2-512bdb255bc4

STIX ID: report--03043d7a-5036-5dfa-bab2-512bdb255bc4

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A high-severity vulnerability (CVE-2026-0628) in Google Chrome’s integrated Gemini AI panel allowed malicious browser extensions to inject JavaScript into the privileged Gemini side panel via the declarativeNetRequest API, enabling silent activation of camera and microphone, screenshots, access to local files, and trusted-panel phishing. Discovered by Unit 42 and responsibly disclosed to Google, a patch was released on 2026-01-05; organizations and users are advised to update Chrome immediately to mitigate the risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.