CVE-2026-0628: Chrome “Gemini Live” Side Panel Injection Bug
ID: 95fb2fc0-1bd5-57c5-8496-9e5f3b10c713
STIX ID: report--95fb2fc0-1bd5-57c5-8496-9e5f3b10c713
Feed Name: SOCRadar Blog
CVE-2026-0628 is a high-severity Chrome/Chromium vulnerability that allows malicious browser extensions to inject script or HTML into the privileged Gemini Live side panel due to insufficient <webview> policy enforcement; vulnerable builds are versions prior to 143.0.7499.192 (with fixes available in 143.0.7499.192/.193 and Extended Stable 142.0.7444.265). The report outlines the extension-led exploitation chain, confirms at least one public proof-of-concept, notes no authoritative confirmation of widespread in-the-wild exploitation, and recommends immediate patching plus stronger extension allowlisting and monitoring as mitigations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
