New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
ID: ea073c48-3bff-5057-8169-eef9284c3d18
STIX ID: report--ea073c48-3bff-5057-8169-eef9284c3d18
Feed Name: The Hacker News
Cybersecurity researchers disclosed CVE-2026-0628, an insufficient policy enforcement flaw in Chrome's WebView/Gemini Live side panel that could let a malicious extension inject scripts into a privileged browser component and escalate privileges to access camera, microphone, screenshots, and local files; the issue (CVSS 8.8) was reported by Unit 42 and patched by Google in January 2026. The report highlights how integrating AI/agentic features into high-privilege browser contexts increases attack surface and enables novel prompt-injection and persistence risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
