SOCRadar®[verified]@socradarDisclosure
The post announces a critical Chrome vulnerability (CVE-2026-0628 with CVSS 8.8) that allows malicious extensions to hijack the Gemini Live AI panel and silently access local files, cameras, and microphones, but provides no exploit, patch, or active exploitation details.
PurpleOps[verified]@PurpleOps_ioDisclosure
A newly disclosed CVE-2026-0628 allows Chrome extensions to hijack the Gemini panel, with mitigation steps outlined in the linked write‑up.
ThreatSynop[verified]@ThreatSynopPatch
Chrome’s Gemini AI panel vulnerability (CVE‑2026‑0628) lets low‑permission extensions gain elevated privileges, and Google has released a patch to address the issue.
吴说区块链[verified]@wublockchain12Patch
GoPlus reports a Chrome extension privilege‑escalation flaw (CVE‑2026‑0628) with malware capabilities; Google has released patches in specific Chrome releases and urges users to upgrade.
kokumօtօ[verified]@__kokumotoDisclosure
A CVE-2026-0628 vulnerability in Chrome’s Gemini allowed remote access to a user’s camera and microphone via the declarativeNetRequest API; it was reported on 2025‑10‑23 and patched on 2026‑01‑05.
ThreatSynop[verified]@ThreatSynopPatch
CVE‑2026‑0628 enables malicious Chrome extensions to inject JavaScript into Gemini Live, granting file access and other privileged actions; Google has patched the flaw in Chrome 143, urging users to update.
ThreatSynop[verified]@ThreatSynopDisclosure
Unit42 discloses CVE-2026-0628, a Chrome Gemini panel flaw that allows low‑permission extensions to hijack the AI panel for OS‑level access, and notes that Google patched the issue in early January 2026.
ZettaWire[verified]@ZettaWireDisclosure
The post announces a high‑severity CVE‑2026‑0628 that lets malicious extensions hijack the Gemini Live AI assistant to access local files, computer camera, and microphone, and notes that the issue is fixed in Chrome 143.