Unit 42 researchers discovered CVE-2026-0628, a high-severity vulnerability in Chrome's Gemini Live panel that allowed malicious browser extensions to hijack the AI side panel via the declarativeNetRequest API. Because the Gemini panel runs with elevated browser-level privileges, an attacker could exploit this to access the

9m read time From unit42.paloaltonetworks.com
Post cover image
Table of contents
Executive SummaryAI Browsers: A New Wave of ProductivityFusing AI Into the Browser: Security HazardsExtensions Security: Understanding the Threat ModelThe Vulnerability in Gemini Live in ChromePrivilege Escalation: Camera, Files, Screenshots and MoreRisk Averted: How Could This Have Turned Out?Timeline: From Discovery to FixConclusion

Sort: