CVE-2026-0628
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
Vulnerabilities · 196 days ago
A high-severity CVE-2026-0628 in Chrome's Gemini feature allowed malicious extensions with minimal permissions to hijack the Gemini Live panel and access local files, camera/microphone, and screenshots, enabling privilege escalation and privacy invasion. Google patched the flaw in early January after coordinated disclosure.
CVSS 8.8 HIGH: insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who… EPSS 7% (93rd percentile).
4 sources covering this story
New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
Chrome CVE-2026-0628 let malicious extensions hijack Gemini panel for privilege escalation, local file access, and surveillance.
Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
Malicious extensions could hijack the Gemini Live in Chrome feature to spy on users and steal their files.
Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel
A high-severity CVE-2026-0628 in Chrome's Gemini allowed local file access and privacy invasion.
Bug in Google's Gemini AI Panel Opens Door to Hijacking
Attackers could have exploited the vulnerability to escalate privileges, violate user privacy while browsing, and access sensitive resources
Part of the PlainSec briefing for 2026-03-04