logo

New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel

ID: ea073c48-3bff-5057-8169-eef9284c3d18

STIX ID: report--ea073c48-3bff-5057-8169-eef9284c3d18

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-03-02

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed CVE-2026-0628, an insufficient policy enforcement flaw in Chrome's WebView/Gemini Live side panel that could let a malicious extension inject scripts into a privileged browser component and escalate privileges to access camera, microphone, screenshots, and local files; the issue (CVSS 8.8) was reported by Unit 42 and patched by Google in January 2026. The report highlights how integrating AI/agentic features into high-privilege browser contexts increases attack surface and enables novel prompt-injection and persistence risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.