logo

CVE-2026-0628: Chrome “Gemini Live” Side Panel Injection Bug

ID: 95fb2fc0-1bd5-57c5-8496-9e5f3b10c713

STIX ID: report--95fb2fc0-1bd5-57c5-8496-9e5f3b10c713

Feed Name: SOCRadar Blog

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

CVE-2026-0628 is a high-severity Chrome/Chromium vulnerability that allows malicious browser extensions to inject script or HTML into the privileged Gemini Live side panel due to insufficient <webview> policy enforcement; vulnerable builds are versions prior to 143.0.7499.192 (with fixes available in 143.0.7499.192/.193 and Extended Stable 142.0.7444.265). The report outlines the extension-led exploitation chain, confirms at least one public proof-of-concept, notes no authoritative confirmation of widespread in-the-wild exploitation, and recommends immediate patching plus stronger extension allowlisting and monitoring as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.