Security boffins have discovered a high-severity bug in Google Chrome that allowed malicious extensions to hijack its Gemini Live AI panel and inherit privileges they were never meant to have. The flaw, tracked as CVE-2026-0628, was uncovered by researchers at Palo Alto Networks' Unit 42 who found that rogue Chrome extensions could manipulate how the browser handled requests to the embedded Gemini Live side panel. By exploiting the way Chrome handles extension network rules, a malicious add-on with fairly standard permissions could intercept and tamper with traffic headed for the Gemini panel, slipping its own JavaScript into a far more trusted part of the browser. Gemini Live, built into Chrome as an interactive AI panel, isn't just a chatbot bolted onto a tab. It's tightly integrated into the browser to grab screenshots, read local files, and turn on your camera or microphone when asked. That's handy if you're using it as intended, but less so if a sketchy extension manages to ride along and inherit the same level of access, stepping well beyond the permissions add-ons are supposed to have. "Since the Gemini app relies on performing actions for legitimate purposes, hijacking the Gemini panel allows privileged access to system resources that an extension would not normally have," said Gal Weizman, security researcher at Palo Alto Networks. In effect, a malicious extension could have turned on a webcam or microphone, sifted through local files, taken screenshots, or slipped p...
Chrome Gemini panel became privilege escalator for rogue extensions
The Register
·Carly Page
·Published Mar 3, 2026
·Updated
Affected Software
1 affected component
Google Chrome<=143.0.7499.192, <=143.0.7499.193
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity bug in Google Chrome that allows malicious extensions to hijack the Gemini Live AI panel.
2
What security implications are discussed?
The vulnerability enables rogue extensions to elevate their privileges and access functionalities they are not supposed to have.
3
What products or software are affected?
The bug affects specific versions of Google Chrome, particularly versions up to 143.0.7499.193.
4
What is the CVE identifier for this vulnerability?
The vulnerability is tracked under the identifier CVE-2026-0628.
5
Who discovered this vulnerability in Google Chrome?
The vulnerability was discovered by security researchers, referred to as 'security boffins' in the article.