Last seen March 2, 2026

Gemini Privilege Escalation Vulnerability

CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.

Technical Severity
Low severity
Lifecycle Status

STABLE

What Happened

CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.

Why This Matters

The evidence matters to defenders using Gemini because it could allow an attacker to gain additional privileges.

Recommended Action

Confirm whether Bug is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Mar 02, 2026 05:30

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: UNKNOWN

Primary entities:

GoogleChrome browserGeminiGemini AI panelRemote Code ExecutionBug

Authoritative Intelligence

CVE CVE-2026-0628 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

Timeline

  • Incident first seen
    Mar 02, 2026 05:30

    BugSkan first recorded this incident.

  • Bug in Google's Gemini AI Panel Opens Door to Hijacking - Dark Reading
    Mar 02, 2026 05:30

    darkreading.com · Vulnerability

Sources

Bug in Google's Gemini AI Panel Opens Door to Hijacking - Dark Reading

darkreading.com · Mar 02, 2026 05:30

CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence