logo

Chrome security flaw enabled spying via Gemini Live assistant

ID: 0a4b5a86-fbad-54e8-8a44-7560a1cd0764

STIX ID: report--0a4b5a86-fbad-54e8-8a44-7560a1cd0764

Feed Name: Security Affairs

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-22

Author: Pierluigi Paganini

...
...

Palo Alto Networks disclosed CVE-2026-0628, a Chrome vulnerability in the Gemini Live side panel that allowed malicious extensions with basic permissions to inject code into a privileged AI assistant panel, enabling spying (camera/microphone), screenshots, and access to local files; the issue was responsibly disclosed in October 2025 and patched in Chrome 143 in January 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.