Chrome Gemini Spy Vulnerability Exposed

💡Gemini bug lets Chrome extensions spy on your data—security alert for AI devs.
⚡ 30-Second TL;DR
What Changed
Gemini AI feature bug enables extension spying
Why It Matters
AI practitioners using Gemini integrations in Chrome must prioritize security audits. Potential for widespread data breaches in extension ecosystem.
What To Do Next
Audit Chrome extensions using Gemini API and update Chrome immediately.
Key Points
- •Gemini AI feature bug enables extension spying
- •High-severity risk of data exposure
- •Affects Chrome users; protection steps needed
🧠 Deep Insight
Background and context from public sources — not the original article. 7 sources cited.
🔑 Enhanced Key Takeaways
- •The vulnerability is identified as CVE-2026-0628, specifically affecting Chrome's Gemini Live panel, allowing malicious extensions using declarativeNetRequests API to inject JavaScript and escalate privileges.[1]
- •Exploitation enabled unauthorized access to camera, microphone, local files, screenshots of HTTPS websites, and phishing via the hijacked panel, as demonstrated in proof-of-concept attacks.[1][6]
- •Palo Alto Networks Unit 42 responsibly disclosed the flaw to Google, who patched it in early January 2026 before public disclosure.[1]
🛠️ Technical Deep Dive
- •Malicious extensions with basic declarativeNetRequests permissions could intercept and inject JavaScript into the Gemini Live panel, unlike ordinary tabs where such injection grants no special powers.[1]
- •The Gemini panel in Chrome is hooked with elevated capabilities including local file reads, camera/microphone access without consent, HTTPS tab screenshots, and complex task execution.[1]
- •Attack relied on the panel's privileged environment versus standard web app tabs, enabling privilege escalation from basic extension permissions.[1]
🔮 Future ImplicationsAI analysis grounded in cited sources
⏳ Timeline
📎 Sources (7)
Factual claims are grounded in the sources below. Forward-looking analysis is AI-generated interpretation.
- unit42.paloaltonetworks.com — Gemini Live in Chrome Hijacking
- tenable.com — The Trifecta How Three New Gemini Vulnerabilities in Cloud Assist Search Model and Browsing
- securityaffairs.com — Google State Backed Hackers Exploit Gemini AI for Cyber Recon and Attacks
- malwarebytes.com — Gemini AI Flaws Could Have Exposed Your Data
- csoonline.com — Silent Google API Key Change Exposed Gemini AI Data
- securityweek.com — Vulnerability Allowed Hijacking Chromes Gemini Live AI Assistant
- darkreading.com — Bug Google Gemini AI Panel Hijacking
Weekly AI Recap
Read this week's curated digest of top AI events →
👉Related Updates
AI-curated news aggregator. All content rights belong to original publishers.
Original source: ZDNet AI ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
Weekly AI briefing
One email a week. Unsubscribe anytime.



