Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome’s AI Assistant Vulnerability Patched to Prevent Risks

Chrome’s AI Assistant Vulnerability Patched to Prevent Risks

Posted on March 2, 2026 By CWS

A recent report by Palo Alto Networks has revealed a vulnerability in Chrome that could have potentially allowed malicious extensions to compromise the browser’s AI assistant, Gemini Live. This flaw had the potential to spy on users and extract sensitive data.

Gemini Live’s Advanced Capabilities

Gemini Live is an AI assistant integrated into Chrome’s side panel, designed to enhance user experience by summarizing web content, performing tasks, and understanding the context of active web pages. This AI assistant is capable of executing complex operations due to its direct access to the user’s browsing environment.

The extensive capabilities of Gemini Live, which include viewing the web page as the user does and leveraging contextual instructions, introduced new security risks, as explained by Palo Alto Networks.

Security Flaw Details and Exploitation Risks

The vulnerability, identified as CVE-2026-0628, was discovered and later patched in Chrome version 143. It allowed malicious extensions to inject JavaScript into the Gemini Live panel, potentially granting access to sensitive functions.

To exploit this flaw, an extension would need specific permissions via the declarativeNetRequests API, commonly used for legitimate purposes like blocking harmful requests. This API is enabled by default for interactions with Gemini content, thus posing a risk.

The vulnerability could have led to unauthorized access to local files, screenshots, camera, and microphone, effectively turning Gemini Live into a tool for phishing and unauthorized data access.

Response and Security Measures

Palo Alto Networks reported this critical issue to Google in October. Google responded by releasing a security patch in January, addressing the vulnerability in Chrome versions for Windows, macOS, and Linux.

This incident highlights the importance of continuous security assessments in AI-powered browser components and the need for robust protection against potential exploitation.

The patch ensures that Gemini Live’s powerful functionalities are secure from unauthorized access, maintaining user trust in AI enhancements within browsers.

As AI continues to evolve within web browsers, users can expect ongoing improvements in both capabilities and security measures, ensuring a safer and more efficient browsing experience.

Security Week News Tags:AI assistant, browser security, Chrome, CVE-2026-0628, Cybersecurity, data privacy, Gemini Live, JavaScript injection, Palo Alto Networks, Vulnerability

Post navigation

Previous Post: OCRFix Botnet Trojan Uses Blockchain for Stealth Operations
Next Post: AWS Enhances Security Hub with Cross-Domain Integration

Related Posts

161,000 People Impacted by Krispy Kreme Data Breach 161,000 People Impacted by Krispy Kreme Data Breach Security Week News
Logitech Confirms Data Breach Following Designation as Oracle Hack Victim Logitech Confirms Data Breach Following Designation as Oracle Hack Victim Security Week News
Washington Post Says Nearly 10,000 Employees Impacted by Oracle Hack Washington Post Says Nearly 10,000 Employees Impacted by Oracle Hack Security Week News
Chinese APT ‘Phantom Taurus’ Targeting Organizations With Net-Star Malware Chinese APT ‘Phantom Taurus’ Targeting Organizations With Net-Star Malware Security Week News
User Data Compromised in SoundCloud Hack  User Data Compromised in SoundCloud Hack  Security Week News
Cyera Raises 0 Million to Expand AI-Powered Data Security Platform Cyera Raises $540 Million to Expand AI-Powered Data Security Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI Safety Leadership in Flux as Director Resigns
  • Hackers Exploit Government Sites for Malware Distribution
  • Cruciferra Crypter: An Emerging Threat to Windows Security
  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark