Google has patched a high-severity vulnerability (CVE-2026-0628) in the Gemini AI side panel within Chrome, discovered by Palo Alto Networks' Unit 42. The flaw allowed malicious browser extensions with only basic permissions to escalate privileges via the declarativeNetRequests API, enabling JavaScript injection into the

5m read timeFrom darkreading.com
Post cover image
Table of contents
The Gemini AI Security Flaw & Its FixAgentic AI Browsers Add Security Risk

Sort: