CVE-2026-0628Disclosure(google / chrome)

CRITICALCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 29 mentions and remains active

Immediate actions

  • Patch google chrome systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome

Threat summary

  • Active exploitation appears in 5 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 98 mentions across 27 observed days

What's happening

  • Active exploitation reported across 5 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 49 signals
  • Technical details provided in 83 signals
  • Disclosure: 46 classified signals
  • General: 11 classified signals
  • Peaked 25d ago at 29 mentions (2026-03-03); latest day: 1
  • 98 total mentions across 27 days

Affected systems

Vendors
Products
chrome

Deep dive

Activity timeline98 mentions / 27d
07152229Mentions · 2026-03-02: 20Mentions · 2026-03-03: 29Mentions · 2026-03-04: 5Mentions · 2026-03-05: 2Mentions · 2026-03-06: 2Mentions · 2026-03-07: 8Mentions · 2026-03-09: 2Mentions · 2026-03-10: 1Mentions · 2026-03-11: 2Mentions · 2026-03-12: 3Mentions · 2026-03-15: 2Mentions · 2026-03-26: 1Mentions · 2026-03-28: 1Mentions · 2026-04-08: 1Mentions · 2026-04-09: 2Mentions · 2026-04-15: 1Mentions · 2026-04-19: 1Mentions · 2026-04-26: 1Mentions · 2026-05-01: 2Mentions · 2026-05-02: 1Mentions · 2026-05-05: 1Mentions · 2026-05-07: 1Mentions · 2026-09-16: 1Mentions · 2026-09-17: 1Mentions · 2026-09-19: 4Mentions · 2026-09-21: 2Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-03-02: 1PoC Mentioned / Linked · 2026-03-03: 1PoC Mentioned / Linked · 2026-09-21: 1Exploit Tool / Code · 2026-03-07: 1Active Exploitation · 2026-04-08: 1Active Exploitation · 2026-04-09: 1Active Exploitation · 2026-05-02: 1Active Exploitation · 2026-09-16: 1Active Exploitation · 2026-09-22: 1Patch / Workaround · 2026-03-02: 12Patch / Workaround · 2026-03-03: 16Patch / Workaround · 2026-03-04: 2Patch / Workaround · 2026-03-05: 1Patch / Workaround · 2026-03-07: 2Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-15: 1Patch / Workaround · 2026-03-26: 1Patch / Workaround · 2026-03-28: 1Patch / Workaround · 2026-04-08: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-05-01: 2Patch / Workaround · 2026-05-02: 1Patch / Workaround · 2026-05-07: 1Patch / Workaround · 2026-09-16: 1Patch / Workaround · 2026-09-19: 3Patch / Workaround · 2026-09-21: 2Technical Details · 2026-03-02: 18Technical Details · 2026-03-03: 26Technical Details · 2026-03-04: 4Technical Details · 2026-03-05: 2Technical Details · 2026-03-06: 1Technical Details · 2026-03-07: 7Technical Details · 2026-03-09: 2Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-12: 3Technical Details · 2026-03-15: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-28: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-09: 2Technical Details · 2026-04-19: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-07: 1Technical Details · 2026-09-16: 1Technical Details · 2026-09-19: 3Technical Details · 2026-09-21: 2Technical Details · 2026-09-22: 103-0203-0403-0603-0903-1103-1503-2804-0904-1905-0105-0509-1609-1909-22
Signal classification6 categories
Disclosure
4646.9%
Patch
3434.7%
General
1111.2%
Active Exploitation
55.1%
Exploit
11.0%
PoC
11.0%
Referenced assets44 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-0220
Disclosure13General1Patch6
2026-03-0329
Disclosure11General5Patch13
2026-03-045
Disclosure3Patch2
2026-03-052
Disclosure1Patch1
2026-03-062
Disclosure2
2026-03-078
Disclosure4Exploit1General1Patch2
2026-03-092
Disclosure2
2026-03-101
Patch1
2026-03-112
Disclosure2
2026-03-123
Disclosure3
2026-03-152
General1Patch1
2026-03-261
Patch1
2026-03-281
Patch1
2026-04-081
Active Exploitation1
2026-04-092
Active Exploitation1Disclosure1
2026-04-151
General1
2026-04-191
Disclosure1
2026-04-261
General1
2026-05-012
Disclosure1Patch1
2026-05-021
Active Exploitation1
2026-05-051
Disclosure1
2026-05-071
Patch1
2026-09-161
Active Exploitation1
2026-09-171
General1
2026-09-194
Disclosure1Patch3
2026-09-212
Patch1PoC1
2026-09-221
Active Exploitation1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    ⚠️ A new Google Chrome flaw (CVE-2026-0628, CVSS 8.8) could let a malicious extension inject code into the Gemini side panel due to weak WebView policy enforcement. Successful exploitation enabled privilege escalation and potential access to the camera, microphone, screenshots, and local files. 🔗 Details → https://thehackernews.com/2026/03/new-chrome-vulnerability-let-malicious.html

    Post summary

    A new Chrome vulnerability (CVE-2026-0628) allows malicious extensions to inject code into the Gemini side panel, enabling privilege escalation and access to camera, microphone, screenshots, and local files.

    36132035120.6K
    1.1M followersView on X
  • Unit 42@Unit42_Intel
    Patch

    Our research uncovered CVE-2026-0628, a high severity vulnerability in Chrome Gemini, allowing local file access. Google has issued a fix. Read the full analysis: https://bit.ly/4rHlQZW https://t.co/0Hxx3VTf63

    Post summary

    Researchers disclosed a high‑severity local file access flaw in Chrome Gemini (CVE‑2026‑0628); Google has released a patch and a full analysis is available at the provided link.

    115037146.0K
    66.9K followersView on X
  • Cyber_OSINT@Cyber_O51NT
    Disclosure

    Unit 42 reports a Chrome vulnerability (CVE-2026-0628) allowing extensions to hijack Gemini’s new panel, illustrating agentic browser risks and GenAI-enabled abuse. https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/

    Post summary

    Unit 42 announced a new Chrome vulnerability (CVE-2026-0628) that enables extensions to hijack Gemini’s panel, highlighting browser risks.

    01062628
    21.5K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Common architectural pattern across four Q1 2026 AI assistant vulnerabilities (CVE-2026-26144, CVE-2026-0628, CVE-2026-24307, PleaseFix) https://blog.barrack.ai/ai-copilot-attack-surface/

    Post summary

    The post announces a shared architectural pattern among four Q1 2026 AI assistant vulnerabilities, listing their CVE IDs and a blog link for additional context, without specifying exploitation details or mitigation.

    03030586
    32.8K followersView on X
  • SOCRadar®@socradar
    Disclosure

    A critical Chrome vulnerability (CVE-2026-0628, CVSS 8.8) lets malicious extensions hijack the Gemini Live AI panel. Attackers can silently access local files, cameras, and microphones without consent. Read more at the link below. https://hubs.la/Q045lq9s0 #CyberSecurity #ThreatIntel #CVE

    Post summary

    The post announces a critical Chrome vulnerability (CVE-2026-0628 with CVSS 8.8) that allows malicious extensions to hijack the Gemini Live AI panel and silently access local files, cameras, and microphones, but provides no exploit, patch, or active exploitation details.

    02040384
    5.6K followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    🚨 𝐅𝐫𝐞𝐬𝐡 𝐂𝐕𝐄 𝐚𝐥𝐞𝐫𝐭 𝐣𝐮𝐬𝐭 𝐢𝐧! Uncover how CVE-2026-0628 lets extensions hijack the Chrome Gemini panel, and learn practical steps to mitigate this evolving browser threat. 🌐 Explore the write-up → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/cve-2026-0628-chrome-extension-vulnerability/ What’s your take? Share with us!

    Post summary

    A newly disclosed CVE-2026-0628 allows Chrome extensions to hijack the Gemini panel, with mitigation steps outlined in the linked write‑up.

    01031235
    67 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Bug in Chrome’s Gemini AI panel let low-permission extensions hijack high-privilege features (CVE-2026-0628) Dark Reading reports CVE-2026-0628 allowed a malicious Chrome extension with only basic permissions to inject into the Gemini Live side panel and inherit elevated capabilities (screenshots, camera/mic access, and local file/directory access). Google has patched the issue, underscoring that AI “agentic” browser surfaces become new privileged attack planes that need strict extension controls and rapid patching. 🎯 Target: Global/Google Chrome users #️⃣ Category: #Vulnerability #AI_Threats #BlueTeam 🔗 URL: https://www.darkreading.com/endpoint-security/bug-google-gemini-ai-panel-hijacking

    Post summary

    Chrome’s Gemini AI panel vulnerability (CVE‑2026‑0628) lets low‑permission extensions gain elevated privileges, and Google has released a patch to address the issue.

    11030260
    244 followersView on X
  • 吴说区块链@wublockchain12
    Patch

    GoPlus 发出安全警报称,Chrome 浏览器存在编号为 CVE-2026-0628 的漏洞,恶意扩展程序可通过 Gemini Live 面板提升权限,在未经用户许可情况下访问摄像头、麦克风、截取屏幕截图及读取本地文件。谷歌已于 2026 年 1 月初在 Windows/Mac 版本 143.0.7499.192/.193 及 Linux 版本 143.0.7499.192 中修复该漏洞,建议用户立即检查并升级 Chrome 至上述或更高版本。https://www.wublock123.com/index.php?m=content&c=index&a=show&catid=6&id=57470

    Post summary

    GoPlus reports a Chrome extension privilege‑escalation flaw (CVE‑2026‑0628) with malware capabilities; Google has released patches in specific Chrome releases and urges users to upgrade.

    100212.6K
    174.7K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    ChromeのGeminiに被疑者のカメラとマイクに遠隔からアクセスできる脆弱性があった。CVE-2026-0628。2025/10/23報告、2026/1/5修正。広告ブロック等に使用されるdeclarativeNetRequest API権限を使うとGeminiのサーバとの通信を傍受し注入ができた。 https://cybersecuritynews.com/chrome-gemini-vulnerability/

    Post summary

    A CVE-2026-0628 vulnerability in Chrome’s Gemini allowed remote access to a user’s camera and microphone via the declarativeNetRequest API; it was reported on 2025‑10‑23 and patched on 2026‑01‑05.

    00022902
    7.3K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 Chrome Bug Let Malicious Extensions Hijack Gemini Live to Spy and Steal Files A flaw (CVE-2026-0628) could let a malicious Chrome extension inject JavaScript into the Gemini Live side-panel via declarativeNetRequests permissions, effectively inheriting Gemini’s privileged capabilities (read local files, screenshots, camera/mic access) for spying, exfiltration, or phishing. Google patched it in Chrome 143 (January), making rapid browser/extension hygiene critical for users relying on in-browser AI assistants. 🎯 Target: Global/Chrome Users & Enterprises #️⃣ Category: #Vulnerability #AI_Threats 🔗 URL: https://www.securityweek.com/vulnerability-allowed-hijacking-chromes-gemini-live-ai-assistant/

    Post summary

    CVE‑2026‑0628 enables malicious Chrome extensions to inject JavaScript into Gemini Live, granting file access and other privileged actions; Google has patched the flaw in Chrome 143, urging users to update.

    11020207
    244 followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Chrome Gemini panel flaw let low-permission extensions hijack “Gemini Live” for OS-level access (CVE-2026-0628) Unit 42 disclosed CVE-2026-0628 where an extension using basic `declarativeNetRequest` rules could inject JavaScript into the Gemini Live side panel (http://gemini.google.com/app) and inherit the panel’s privileged capabilities—enabling screenshots, camera/mic access, and local file/directory access. Google fixed it in early January 2026; treat AI browser panels as high-privilege surfaces and lock down extension policies in enterprise fleets. 🎯 Target: Global/Google Chrome users (esp. enterprises with extensions) #️⃣ Category: #Vulnerability #AI_Threats #BlueTeam 🔗 URL: https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/

    Post summary

    Unit42 discloses CVE-2026-0628, a Chrome Gemini panel flaw that allows low‑permission extensions to hijack the AI panel for OS‑level access, and notes that Google patched the issue in early January 2026.

    01021161
    244 followersView on X
  • Luigi Basemi 🏅@LBasemi
    Patch

    🧵🔎Il tuo assistente AI è una spia — e #Chrome glielo ha permesso Una vulnerabilità di Chrome recentemente corretta (CVE-2026-0628) ha trasformato l'assistente AI Gemini Live di #Google in uno strumento di spionaggio silenzioso. https://t.co/ESVaynrcvR

    Post summary

    The tweet reports that Chrome's recent patch for CVE‑2026‑0628 revealed it had allowed Gemini Live AI to act as a silent spy, yet no active exploitation or technical details are provided.

    10011180
    10.8K followersView on X
  • ZettaWire@ZettaWire
    Disclosure

    Researchers identify high-severity Chrome vulnerability CVE-2026-0628 that allowed malicious extensions to hijack the Gemini Live AI assistant. The flaw, now patched in Chrome 143, granted unauthorized access to local files, camera, and microphone. #Google #CyberSecurity

    Post summary

    The post announces a high‑severity CVE‑2026‑0628 that lets malicious extensions hijack the Gemini Live AI assistant to access local files, computer camera, and microphone, and notes that the issue is fixed in Chrome 143.

    10020176
    360 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Chrome Gemini の脆弱性 CVE-2026-0628 の詳細:AI タスク実行のための高権限付与という問題 https://iototsecnews.jp/2026/03/03/chrome-gemini-vulnerability-lets-attackers-access-victims-camera-and-microphone-remotely/ Google Chrome に統合された AI アシスタント Gemini Live において、ユーザーのプライバシーを著しく侵害する恐れのある深刻な脆弱性 CVE-2026-0628 が確認されました。この問題の原因は、Gemini が通常のブラウザタブで動作する場合と、高権限を持つサイドパネル内で動作する場合とで、セキュリティ境界の管理が異なる点にあります。本来であれば、広告ブロックなどで使われるエクステンション用の API (declarativeNetRequests) は、Web サイトに勝手にプログラムを流し込んでも、重要な権限には触れないよう設計されています。 しかし、Gemini サイドパネルは “画面の要約” や “ファイルの読み取り” といった高度な AI 処理を行うために、ブラウザからのカメラ/マイク/ローカル・ファイルへのアクセス権限を特別に付与されていました。この脆弱性を突く、悪意のエクステンションによりパネル内の通信が傍受/改変され、AI に与えられた特権が乗っ取られる状態になっていました。この脆弱性が公開されてから、一定の時間が経過したことで、Unit 42 が詳細を説明したのだと推測されます。 #Chrome #Gemini #Vulnerability #CVE20260628 #AI #ML

    Post summary

    The article announces CVE-2026-0628, detailing how an AI side‑panel in Chrome Gemini can be abused by a malicious extension to grant attackers camera and microphone access, but it does not mention any PoC, exploit code, active exploitation, or patch.

    01020204
    484 followersView on X
  • SC Media@SCMagazine
    Patch

    .@Google patched CVE-2026-0628, a high-severity Chrome flaw that let rogue extensions hijack the Gemini AI panel, inject phishing content and access elevated browser permissions. #cybersecurity #AI #infosec #CISO #ITsecurity https://bit.ly/4bkdm4Z

    Post summary

    Google has released a patch for CVE‑2026‑0628, a high‑severity flaw that allowed malicious extensions to hijack the Gemini AI panel and inject phishing content. No PoC, exploit code, or active exploitation indications are present.

    01020389
    119.4K followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Disclosure

    Chrome Extension Vulnerability Allows Hijacking of Gemini Panel (CVE-2026-0628) Researchers from Unit 42 identified a vulnerability in Chrome that allows malicious extensions to intercept and hijack interactions with the Gemini AI panel. Tracked as CVE-2026-0628, the flaw enables an extension with sufficient permissions to manipulate the Gemini interface, potentially altering prompts, injecting content, or capturing user interactions routed through the panel. The issue highlights a growing attack surface where browser extensions intersect with AI-integrated interfaces, allowing malicious extensions to operate within trusted application contexts. Because Chrome extensions are widely used across enterprise and consumer environments, the vulnerability demonstrates how AI-enabled browser features can introduce new abuse vectors when extension permissions are misused. Source: https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/ #CyberSecurity #ThreatIntel #Chrome #GenAI

    Post summary

    Researchers disclosed CVE‑2026‑0628, a Chrome extension vulnerability that permits malicious extensions to hijack the Gemini AI panel, enabling prompt manipulation and data capture.

    10020142
    188 followersView on X
  • ゆっくりAI広報@yukkuri_ai_pr
    Disclosure

    ブラウザ内AI機能も“攻撃面”になる。 ① ChromeのGemini機能実装に高深刻度の脆弱性(CVE-2026-0628) ② 悪意ある拡張がローカルファイルへ到達する可能性 ③ 教訓:エージェント/AI機能は「権限最小・拡張管理・隔離」が基本 #AI

    Post summary

    The post announces a high‑severity vulnerability in Chrome’s Gemini feature (CVE‑2026‑0628) that could allow malicious extensions to access local files; no exploit evidence, patch details, or PoC code is included.

    1101015
    141 followersView on X
  • Mr.Rabbit@01ra66it
    Disclosure

    CVE-2026-0628:Gemini機能を踏み台に権限昇格→ローカルファイル到達。新機能が橋頭堡化。 #CVE #Chrome #AIsecurity https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/

    Post summary

    A new CVE (CVE-2026-0628) involving Chrome's Gemini feature is disclosed, highlighting privilege escalation and local file access capabilities.

    00021294
    3.3K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Chrome Gemini Panel Flaw Let Malicious Extensions Spy and Steal Local Files (CVE-2026-0628) A high-severity Chrome bug (CVE-2026-0628) let a malicious extension abuse `declarativeNetRequest` to inject JavaScript into the *privileged* Gemini side-panel at `http://gemini.google.com/app`, inheriting access to camera/mic, screenshots, and local files. This matters because it turns “basic-permission” extensions into high-impact surveillance/data-theft tools unless Chrome is patched fleet-wide. 🎯 Target: Global/Chrome Users & Enterprises #️⃣ Category: #Vulnerability #AI_Threats 🔗 URL: https://cybersecuritynews.com/chrome-gemini-vulnerability/

    Post summary

    The post announces CVE‑2026‑0628, describing a Chrome Gemini panel flaw that lets malicious extensions inject JavaScript to gain camera, microphone, screenshot, and local file access, and calls for a fleet‑wide patch.

    1002096
    244 followersView on X
  • ♫Why♥Not♪@Python_s_
    PoC

    🚨 AI SECURITY ALERT DISCLOSED BY: Forever Security PRODUCTS: Google Chrome / Gemini Live Microsoft Edge Perplexity Comet Opera Neon Claude in Chrome CVEs: CVE-2026-0628 — Chrome CVE-2026-55945 — Microsoft Edge IMPACT: A malicious browser extension can abuse trusted browser-agent communication paths and hijack AI-assisted actions without additional user clicks after the extension is installed. AFFECTED VERSIONS: Chrome before 143.0.7499.192 Microsoft Edge before 150.0.4078.48 Specific vulnerable version ranges for Comet, Opera Neon and Claude in Chrome were not published in the research. EXPLOITATION STATUS: Working PoC confirmed. No confirmed in-the-wild exploitation reported. ✅ URGENT ACTION: Update Chrome and Edge immediately. Update Comet, Opera Neon and Claude in Chrome to their latest releases. Audit extensions with broad host access, declarativeNetRequest or debugger permissions and enforce extension allowlisting where possible. SOURCE: Forever Security — BragJack Technical Research https://forever.security/blog/bragjack-attack-hijacks-every-browser-agent/ #CyberSecurity #InfoSec #AISecurity #AIAgents #BrowserSecurity #ThreatIntel #Vulnerability #SecOps #Chrome #MicrosoftEdge #Perplexity #OperaNeon #Claude

    Post summary

    The alert discloses the 'BragJack' vulnerability affecting AI-assisted browser agents across multiple browsers, confirms a working Proof of Concept exists, reports no active exploitation, and urges immediate patching to specific versions along with extension auditing.

    10010200
    226 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgooglechrome---

Explore more