logo

Chrome flaw let extensions hijack Gemini’s camera, mic, and file access

ID: e0508e01-278e-5b3c-a815-f2bae640e05c

STIX ID: report--e0508e01-278e-5b3c-a815-f2bae640e05c

Feed Name: Malwarebytes Blog

Threat Score
70/100

Date Published: 2026-03-03

Date Updated: 2026-04-28

...
...

Researchers disclosed CVE-2026-0628, a flaw in Chrome’s Gemini "Live in Chrome" side panel that allowed basic-permission extensions to tamper with gemini.google.com/app traffic and inject code into a privileged assistant context, enabling actions such as local file enumeration, screenshots, and camera/microphone activation; Google patched the issue in January 2026 and users are advised to update, limit extensions, and monitor for anomalous camera/screenshot activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.