logo

Chrome Gemini panel became privilege escalator for rogue extensions

ID: 463ed069-9121-586e-a90e-ae947a01f0b8

STIX ID: report--463ed069-9121-586e-a90e-ae947a01f0b8

Feed Name: The Register (Security)

Threat Score
65/100

Date Published: 2026-03-03

Date Updated: 2026-04-26

Author: Carly Page

...
...

Security researchers at Palo Alto Networks' Unit 42 uncovered CVE-2026-0628, a Chrome vulnerability that allowed malicious extensions to intercept requests to the integrated Gemini Live AI side panel and inject JavaScript into that trusted context, potentially enabling webcam/microphone access, reading local files, taking screenshots, and injecting phishing content; Google fixed the issue in Chrome 143.0.7499.192 and 143.0.7499.193 and users on updated releases are protected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.