Google fixed a high-severity Chrome vulnerability that could have allowed a malicious extension to hijack the built-in Gemini AI panel, potentially escalating its privileges or conducting phishing attacks, Palo Alto Networks’ Unit 42 disclosed Monday.Unit 42 researchers discovered the flaw, tracked as CVE-2026-0628, which arose due to insufficient policy enforcement in the WebView tag through which the Gemini panel is displayed. The vulnerability has a CVSS score of 8.8.The Gemini panel, or Gemini in Chrome, is undergoing a gradual roll out to Chrome users and allows users to access a Gemini chat interface in a browser sidebar by clicking an icon at the top of the browser. It includes a Gemini Live feature that allows the AI to view tabs the user has open. Users need to opt in to use Gemini in Chrome the first time they open the panel.The vulnerability allows a browser extension with basic permissions set through Chrome’s declaritiveNetRequests API to inject HTML or JavaScript directly into the Gemini panel, Unit 42 explained. Such permissions are typically benign, as injecting code into web pages through the browser does not grant the extension any extra permissions and enables legitimate functions such as ad blocking or displaying a custom theme.However, because the WebView panel delivering content from the Gemini app is built into the browser, hijacking its content can grant access to elevated permissions including the ability to take screenshots of the user’s browser tabs, activate the user’s camera and microphone without prompting for consent and even reaching the local file system.Additionally, the Gemini panel could be made to display phishing content to the user. While this is also possible by injecting phishing content into a normal web page, it is especially dangerous when targeting the Gemini panel due to the panel being a trusted browser component, the researchers noted. “The evolution of browsers integrating AI presets additional risks that add more weight to how dangerous extension-based attacks can be,” the Unit 42 team wrote.The flaw was first reported to Google in October 2025 and fixed on Jan. 6, 2026, with the release of version 143.0.7499.192, with technical details first disclosed this week.
Application security, AI/ML, AI benefits/risks, Vulnerability Management, Patch/Configuration Management

Google Chrome vulnerability risked hijacking Gemini panel by rogue extension
(Credit: IB Photography – stock.adobe.com)

Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds
