Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel

A high-severity CVE-2026-0628 in Chrome's Gemini feature allowed malicious extensions with minimal permissions to hijack the Gemini Live panel and access local files, camera/microphone, and screenshots, enabling privilege escalation and privacy invasion. Google patched the flaw in early January after coordinated disclosure.

Part of the PlainSec briefing for 2026-03-04

Sources