logo

Bug in Google's Gemini AI Panel Opens Door to Hijacking

ID: 270e210a-0377-54c1-a8ad-ff2e4929a248

STIX ID: report--270e210a-0377-54c1-a8ad-ff2e4929a248

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2026-03-02

Date Updated: 2026-04-21

Author: Elizabeth Montalbano

...
...

Google patched CVE-2026-0628, a high-severity flaw in Chrome's Gemini AI side panel that could let malicious extensions with minimal permissions inject JavaScript and escalate privileges to access camera/microphone, take screenshots, and read local files; discovered by Palo Alto Networks Unit 42, the report warns that agentic AI browsers expand the attack surface and calls for native, continuous in-browser security and real-time policy enforcement.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.