Unit42.Paloaltonetworks Vulnerability in Chrome's Gemini Panel Enables Extension Hijacking
Article Content
Browse articles
A vulnerability identified as CVE-2026-0628 in Chrome's Gemini panel allowed attackers to hijack extensions, leading to local file access and privacy violations. Google has issued a patch to address this high-severity flaw, which could have enabled privilege escalation and access to sensitive resources while browsing. Users of the affected Chrome version are advised to update immediately.
Ask AI about this cluster
Answers cite the sources they use
Updated 208d ago How this analysis works
Timeline
2026-01-06
CVE-2026-0628 published
2026-01-08
First public proof of concept released
2026-03-02
Google patched the vulnerability
More articles in this cluster (21)
Following this threat?
Track Google and CVE-2026-0628 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
BragJack Attack Compromises Major Browser AI Assistants The BragJack attack exploits vulnerabilities in the AI assistants of five major browsers: Google Chrome, Microsoft Edge, Opera Neon, Perplexity Comet, and Claude in Chrome. Researchers from Forever Security discovered that these vulnerabilities allow attackers to access sensitive data, control local files, and…
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…