CVE-2026-0628
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
Vulnerabilities & Exploits
Exploits could have enabled privilege escalation, local file access, screenshots and camera/microphone capture.
4 sources · Mar 2
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
The Hacker News
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Chrome CVE-2026-0628 let malicious extensions hijack Gemini panel for privilege escalation, local file access, and surveillance.
originalSecurityWeek
Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files.
originalUnit 42
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel
A high-severity CVE-2026-0628 in Chrome's Gemini allowed local file access and privacy invasion.
originalPart of the PlainSec briefing for 2026-03-03
Every edition of this story: Chrome Gemini Panel Flaw Enables Extension Hijacks