• News/
  • https://www.zdnet.com/article/gemini-live-chrome-bug-hijacks-ai/

This critical Chrome browser vulnerability lets malicious extensions spy on your PC

ZDNet
·
Charlie Osborne
·
Published Mar 13, 2026
·
Updated

Follow ZDNET: Add us as a preferred source on Google. A new vulnerability impacting Google Chrome's Gemini agentic AI feature has been disclosed -- patch now to stay protected. Also: AI agents are fast, loose, and out of control, MIT study finds Disclosed by senior principal security researcher Gal Weizman from Palo Alto Networks' Unit 42 team, the browser vulnerability affects Google Chrome's Gemini AI feature, an artificial intelligence (AI) agentic browser assistant. Tracked as CVE-2026-0628 and deemed high severity, the vulnerability is described as an "insufficient policy enforcement in WebView tag in Google Chrome" issue that, prior to version 143.0.7499.192 of the browser, "allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension." Also: Why scammers say nothing when they call - and how to respond safely The team found that an extension with access to a basic permission set, via the declarativeNetRequests API, could grant permissions that an attacker could exploit to inject JavaScript code into the new Gemini panel browser component. According to the researchers, this vulnerability can be used as part of a broader attack chain targeting Google Chrome users. If, for example, an attacker can convince a target to download and install an innocent-looking browser extension, a malicious extension could exploit the policy problem to hijack Gemini. The AI assistant may then take ac...

Read full article

Affected Software

2 affected components
Google Chrome<143.0.7499.192
Google Chrome>=143.0.7499.192
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a high-severity vulnerability in Google Chrome's Gemini AI feature that allows malicious extensions to potentially compromise user security.

2

What security implications are discussed?

The article highlights the risk of unauthorized spying on users' PCs through the exploitation of the Chrome Gemini vulnerability by malicious extensions.

3

What products or software are affected?

The vulnerability specifically affects Google Chrome version 143.0.7499.192 and earlier versions.

4

What action should users take to protect themselves?

Users are advised to update their Google Chrome browser immediately to the latest version to mitigate the vulnerability.

5

Who is the vendor mentioned in the article?

The vendor mentioned in the article is Google, which develops the Chrome browser.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203