Story perspectives
Google Chrome Patch Fixes Major AI-Driven Security Flaw
3/3/2026
1 of 1
Story summary
- CVE-2026-0628 affects Google Chrome's Gemini feature, enabling privilege escalation and local file access due to insufficient WebView tag policy enforcement.
- Malicious extensions could hijack the Gemini panel and access the camera, microphone, and screenshots.
- Gal Weizman, a cybersecurity researcher, identified the flaw and reported it to Google in October 2025.
- Google patched the vulnerability in January 2026.
- The integration of AI in browsers raises new security risks.
