Chrome flaw let extensions hijack Gemini’s camera, mic, and file access
ID: e0508e01-278e-5b3c-a815-f2bae640e05c
STIX ID: report--e0508e01-278e-5b3c-a815-f2bae640e05c
Feed Name: Malwarebytes Blog
Threat Score
Researchers disclosed CVE-2026-0628, a flaw in Chrome’s Gemini "Live in Chrome" side panel that allowed basic-permission extensions to tamper with gemini.google.com/app traffic and inject code into a privileged assistant context, enabling actions such as local file enumeration, screenshots, and camera/microphone activation; Google patched the issue in January 2026 and users are advised to update, limit extensions, and monitor for anomalous camera/screenshot activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
