Follow ZDNET: Add us as a preferred source on Google. A new vulnerability impacting Google Chrome's Gemini agentic AI feature has been disclosed -- patch now to stay protected. Also: AI agents are fast, loose, and out of control, MIT study finds Disclosed by senior principal security researcher Gal Weizman from Palo Alto Networks' Unit 42 team, the browser vulnerability affects Google Chrome's Gemini AI feature, an artificial intelligence (AI) agentic browser assistant. Tracked as CVE-2026-0628 and deemed high severity, the vulnerability is described as an "insufficient policy enforcement in WebView tag in Google Chrome" issue that, prior to version 143.0.7499.192 of the browser, "allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension." Also: Why scammers say nothing when they call - and how to respond safely The team found that an extension with access to a basic permission set, via the declarativeNetRequests API, could grant permissions that an attacker could exploit to inject JavaScript code into the new Gemini panel browser component. According to the researchers, this vulnerability can be used as part of a broader attack chain targeting Google Chrome users. If, for example, an attacker can convince a target to download and install an innocent-looking browser extension, a malicious extension could exploit the policy problem to hijack Gemini. The AI assistant may then take ac...
This critical Chrome browser vulnerability lets malicious extensions spy on your PC
ZDNet
·Charlie Osborne
·Published Mar 13, 2026
·Updated
Affected Software
2 affected components
Google Chrome<143.0.7499.192
Google Chrome>=143.0.7499.192
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a high-severity vulnerability in Google Chrome's Gemini AI feature that allows malicious extensions to potentially compromise user security.
2
What security implications are discussed?
The article highlights the risk of unauthorized spying on users' PCs through the exploitation of the Chrome Gemini vulnerability by malicious extensions.
3
What products or software are affected?
The vulnerability specifically affects Google Chrome version 143.0.7499.192 and earlier versions.
4
What action should users take to protect themselves?
Users are advised to update their Google Chrome browser immediately to the latest version to mitigate the vulnerability.
5
Who is the vendor mentioned in the article?
The vendor mentioned in the article is Google, which develops the Chrome browser.