Chrome Gemini panel became privilege escalator for rogue extensions
ID: 463ed069-9121-586e-a90e-ae947a01f0b8
STIX ID: report--463ed069-9121-586e-a90e-ae947a01f0b8
Feed Name: The Register (Security)
Security researchers at Palo Alto Networks' Unit 42 uncovered CVE-2026-0628, a Chrome vulnerability that allowed malicious extensions to intercept requests to the integrated Gemini Live AI side panel and inject JavaScript into that trusted context, potentially enabling webcam/microphone access, reading local files, taking screenshots, and injecting phishing content; Google fixed the issue in Chrome 143.0.7499.192 and 143.0.7499.193 and users on updated releases are protected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
