CVE-2026-0628 Privilege Escalation Vulnerability affecting Chrome
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. The supported impact is code injection. Reported affected versions include
What Happened
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. The supported impact is code injection. Reported affected versions include
Why This Matters
Publisher reporting describes a concrete security event. BugSkan could not yet bind it to a CVE or affected version, so treat the source details as the current record.
Recommended Action
No confirmed vendor remediation is available in the current evidence. Identify deployments of Chrome matching the evidenced affected versions: <143.0.7499.192.
Exposure
Exposure unknown
Mar 02, 2026 05:30
Exposure reason: This incident does not currently match a technology in My AI Stack.
Exploitation status: UNKNOWN
Primary entities:
Authoritative Intelligence
Public GitHub References
Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.
GitHub API error: API rate limit exceeded for 68.178.145.130. (But here's the good news: Authenticated requests get a higher rate limit. Check out the documentation for more details.)
Timeline
-
Incident first seen
Mar 02, 2026 05:30BugSkan first recorded this incident.
-
Bug in Google's Gemini AI Panel Opens Door to Hijacking - Dark Reading
Mar 02, 2026 05:30darkreading.com · Vulnerability
Sources
darkreading.com · Mar 02, 2026 05:30
CVE-2026-0628 details a high-severity privilege escalation flaw in Google's Gemini AI panel within the Chrome browser, enabling malicious extensions to inject JavaScript code. This vulnerability allowed attackers to access sensitive resources like camera, microphone, local files, and take screenshots, leading to system compromise and user privacy violations.
Open publisher sourceMy AI Stack Match
Create an account to see which incidents overlap with your AI stack.