Chrome Gemini Vulnerability Lets Attackers Access Victims’ Camera and Microphone Remotely
## Security Vulnerability in Chrome's Gemini AI Assistant
Security Vulnerability in Chrome's Gemini AI Assistant
A significant security vulnerability identified as CVE-2026-0628 has been discovered in Google Chrome's integrated Gemini AI assistant. This flaw potentially exposes users to unauthorized camera and microphone access, local file theft, and phishing attacks without requiring user interaction beyond launching the AI panel.
The vulnerability was discovered by researchers at Palo Alto Networks' Unit 42 and disclosed to Google on October 23, 2025. In response, Google confirmed the issue and released a security patch on January 5, 2026, to address the flaw.
The Gemini Live feature in Chrome is among AI assistants integrated within browsers, similar to Microsoft Copilot in Edge. These assistants function as side panels with advanced capabilities such as webpage summarization and task automation.
The flaw originates from how Chrome handles the declarativeNetRequest API, which is typically used for legitimate purposes like ad-blocking. However, a specific inconsistency in processing requests to hxxps[:]//gemini.google[.]com/app allows extensions to inject JavaScript, potentially hijacking the Gemini panel.
A significant security vulnerability identified as CVE-2026-0628 has been discovered in Google Chrome's integrated Gemini AI assistant.
Once compromised, an attacker can exploit the Gemini panel to perform actions such as:
Activating the camera and microphone for surveillance Capturing screenshots to obtain sensitive data Accessing local files and directories Conducting phishing attacks with high credibility
The integration of AI panels like Gemini alters the risk landscape of extension-based attacks, posing significant security risks in enterprise environments due to potential access to sensitive data.
Google's patch issued on January 5, 2026, mitigates this vulnerability. Users and organizations should ensure that Chrome is updated across all devices to protect against this security threat.
Based on reporting by Cyber Security News.
