Close Menu
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    • Blogging
    • SEO & Digital Marketing
    • WiFi / Internet & Networking
    • Cybersecurity
    • Tech Tools & Mobile / Apps
    • Privacy & Online Earning
    Facebook X (Twitter) Instagram
    Wifi PortalWifi Portal
    Home»Cybersecurity»Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant
    Cybersecurity

    Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant

    adminBy adminMarch 2, 2026No Comments3 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit WhatsApp Email
    Chrome vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A vulnerability in Chrome could have allowed malicious extensions to hijack the browser’s AI assistant to spy on users and exfiltrate data, Palo Alto Networks reports.

    Chrome’s side panel AI assistant, called Gemini Live, was designed to help users by summarizing content in real time, automatically executing specific tasks, and aiding with the contextual understanding of the active webpage.

    “By granting the AI direct, privileged access to the browsing environment, AI browsers are capable of performing complex, multi-step operations that were previously impossible or required several extensions and manual steps,” Palo Alto Networks explains.

    To function as intended, the AI essentially sees what the user sees on the screen and uses the web page for context and instructions, and this expanded capability and privileged access open the door to new risks.

    The vulnerability that Palo Alto Networks uncovered, tracked as CVE-2026-0628 and patched in January in Chrome 143, could have allowed malicious browser extensions to inject JavaScript code into the Gemini Live panel.

    The malicious extension, the cybersecurity firm explains, would require access to a permission set through the declarativeNetRequests API, which allows extensions to intercept and alter HTTPS web requests and responses.

    Advertisement. Scroll to continue reading.

    The capability is meant for legitimate purposes, such as blocking malicious or intrusive requests, and is enabled by default for extensions to interact with content originating from Gemini and loaded in the website’s tab.

    CVE-2026-0628, Palo Alto Networks says, impacted the ability to interact with the contents loaded within the Gemini panel, meaning that JavaScript code would gain access to the AI’s capabilities.

    “These include being able to read local files, take screenshots, access the camera and microphone and more, so the app could perform complex tasks. Being able to intercept it under that setting would have allowed attackers to gain access to these powers too,” Palo Alto Networks explains.

    Because the Gemini Live panel is a component of the browser itself, an attacker could have injected code to start the camera and microphone without user consent, to access local files, to take screenshots of browser tabs, and to hijack the panel and perform a phishing attack.

    “Since the Gemini app relies on performing actions for legitimate purposes, hijacking the Gemini panel allows privileged access to system resources that an extension would not normally have,” Palo Alto Networks explains.

    The cybersecurity firm reported the bug to Google in October. A fix was rolled out in Chrome versions 143.0.7499.192/.193 for Windows and macOS, and Chrome version 143.0.7499.192 for Linux.

    Related: Google Working Towards Quantum-Safe Chrome HTTPS Certificates

    Related: PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence

    Related: Over 300 Malicious Chrome Extensions Caught Leaking or Stealing User Data

    Related: Chrome, Edge Extensions Caught Stealing ChatGPT Sessions

    Allowed Assistant Chromes Gemini hijacking Live vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    Previous ArticleWant Better Google Ads Insights? Try These 6 Reports
    Next Article Google Pixel’s Now Playing feature rolls out as an app, and boy does it look good
    admin
    • Website

    Related Posts

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical

    March 5, 2026

    Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities

    March 5, 2026
    Add A Comment
    Leave A Reply Cancel Reply

    Search Blog
    About
    About

    At WifiPortal.tech, we share simple, easy-to-follow guides on cybersecurity, online privacy, and digital opportunities. Our goal is to help everyday users browse safely, protect personal data, and explore smart ways to earn online. Whether you’re new to the digital world or looking to strengthen your online knowledge, our content is here to keep you informed and secure.

    Trending Blogs

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Pixel Weather app update brings new redesigned icons

    March 5, 2026

    Data center new builds diminish even as demand rises

    March 5, 2026

    Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical

    March 5, 2026
    Categories
    • Blogging (33)
    • Cybersecurity (623)
    • Privacy & Online Earning (92)
    • SEO & Digital Marketing (395)
    • Tech Tools & Mobile / Apps (760)
    • WiFi / Internet & Networking (112)

    Subscribe to Updates

    Stay updated with the latest tips on cybersecurity, online privacy, and digital opportunities straight to your inbox.

    WifiPortal.tech is a blogging platform focused on cybersecurity, online privacy, and digital opportunities. We share easy-to-follow guides, tips, and resources to help you stay safe online and explore new ways of working in the digital world.

    Our Picks

    Russian Ransomware Operator Pleads Guilty in US

    March 5, 2026

    Pixel Weather app update brings new redesigned icons

    March 5, 2026

    Data center new builds diminish even as demand rises

    March 5, 2026
    Most Popular
    • Russian Ransomware Operator Pleads Guilty in US
    • Pixel Weather app update brings new redesigned icons
    • Data center new builds diminish even as demand rises
    • Cisco Drops 48 New Firewall Vulnerabilities, 2 Critical
    • What SMEC’s Data Reveals About AI Max Performance
    • This Ultra phone first to use Sony’s new 200MP camera sensor
    • Cisco Confirms Active Exploitation of Two Catalyst SD-WAN Manager Vulnerabilities
    • Yep, Amazon Is Down | Lifehacker
    © 2026 WifiPortal.tech. Designed by WifiPortal.tech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer

    Type above and press Enter to search. Press Esc to cancel.