Vulnerabilities

Chrome flaw enabled Gemini Panel Privilege Escalation

0

Cybersecurity researchers have revealed details of a now-patched high-severity flaw in Google Chrome that could have allowed malicious extensions to escalate privileges and access sensitive local data.

The vulnerability, tracked as CVE-2026-0628 (CVSS score: 8.8), stemmed from insufficient policy enforcement in Chrome’s WebView tag. Google fixed the issue in January 2026 with version 143.0.7499.192/.193 for Windows and macOS, and 143.0.7499.192 for Linux.

According to the National Vulnerability Database, the flaw enabled attackers to inject scripts or HTML into privileged pages if they convinced users to install a malicious extension.

The issue was discovered by Gal Weizman of Palo Alto Networks Unit 42, who reported it in November 2025. He found that extensions with minimal permissions could exploit the bug to seize control of Chrome’s Gemini Live side panel — launched via the Gemini icon at the top of the browser. Google introduced Gemini integration in September 2025.

Successful exploitation could have allowed attackers to access a victim’s camera and microphone, capture screenshots, and read local files — effectively bypassing browser security boundaries.

Researchers say the vulnerability highlights a growing attack surface as AI-powered features are embedded directly into browsers. While these tools enable content summarization, translation, and automated actions, they also require elevated privileges — creating opportunities for abuse.

By embedding hidden prompts in malicious web pages, attackers could potentially trick AI assistants into executing actions normally blocked by the browser, leading to data theft or code execution. In some cases, instructions could even persist across sessions.

Although browser extensions operate within defined permission models, exploitation of CVE-2026-0628 undermined those safeguards. An attacker could inject arbitrary JavaScript into the Gemini panel via the declarativeNetRequest API, which allows extensions to modify HTTPS requests and responses.

Researchers warned that integrating AI side panels into high-privilege browser contexts may reintroduce classic security risks such as cross-site scripting (XSS), privilege escalation, and side-channel attacks — especially if less-privileged extensions can influence built-in browser components.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

UK warns of Iranian cyber threats

Previous article

Russian Hackers target Signal and WhatsApp accounts

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *