Gemini Privilege Escalation Vulnerability
CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.
What Happened
CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.
Why This Matters
The evidence matters to defenders using Gemini because it could allow an attacker to gain additional privileges.
Recommended Action
Confirm whether Bug is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
Exposure
Exposure unknown
Mar 02, 2026 05:30
Exposure reason: This incident does not currently match a technology in My Interests.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
CVE-2026-0628: 2 public repository references found.
Possible public PoC reference
PoC de CVE-2026-0628: inyeccion de scripts en paginas privilegiadas via webview en Chrome (CWE-862).
0 stars
Open repositoryPublic GitHub reference
Origin CyberAnatomy Spoofing via Malicious WebView - Dissecting CVE-2026-0628 Chromium Extension Privilege Escalation This research provides a comprehensive technical dissection of CVE-2026-0628, a high-severity privilege escalation vulnerability (CVSS v3.1: 8.8) in Chromium's WebView policy enforcement mechanism.
1 stars
Open repositoryA public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.
Timeline
-
Incident first seen
Mar 02, 2026 05:30BugSkan first recorded this incident.
-
Bug in Google's Gemini AI Panel Opens Door to Hijacking - Dark Reading
Mar 02, 2026 05:30darkreading.com · Vulnerability
Sources
darkreading.com · Mar 02, 2026 05:30
CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.
Open publisher sourceRelated Incidents
Other BugSkan incidents that share identifiers, products, or vendors with this report.
My Interests Match
Create an account to see which incidents overlap with your interests.