
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0628 is a high-severity vulnerability involving insufficient policy enforcement in the WebView tag component of Google Chrome, allowing network-based attackers to bypass security restrictions via malicious webpages or extensions. The vulnerability was reported by security researcher Gal Weizman on 2025-11-23 and publicly disclosed on January 6, 2026, when Google released Chrome 143.0.7499.192 to address it. Subsequent research by Palo Alto Networks Unit 42 revealed the flaw's deeper impact: it allowed malicious Chrome extensions to hijack Chrome's Gemini Live AI panel, gaining unauthorized access to users' cameras, microphones, and local files. Affected products include Google Chrome versions prior to 143.0.7499.192 and Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-862 (Missing Authorization) — specifically, insufficient policy enforcement in Chrome's WebView tag component that failed to properly restrict what Chrome extensions could access within the browser's internal panels. Research by Palo Alto Networks Unit 42 detailed how the flaw enabled malicious extensions to inject content into or interact with Chrome's Gemini Live side panel, which operates with elevated permissions including access to camera, microphone, and local file system. The attack vector is network-based and requires user interaction (e.g., installing a malicious extension or visiting a crafted webpage), with no privileges required from the attacker. A public proof-of-concept was published on GitHub, and a detailed technical analysis was released by Unit 42 describing the privilege escalation path through the Gemini panel (Unit 42, Chrome Releases).
Successful exploitation allows a malicious Chrome extension or webpage to bypass Chrome's security policy enforcement, escalating privileges to access the Gemini Live AI panel's elevated permissions. This can result in unauthorized access to the victim's camera and microphone (enabling remote surveillance), access to local files, and potential exfiltration of sensitive data — all with high confidentiality, integrity, and availability impact. The vulnerability affects an estimated 3 billion Chrome users globally, and the Gemini panel's broad device permissions make exploitation particularly dangerous for privacy (Unit 42, Microsoft MSRC).
chrome://extensions); extensions with broad permissions including <all_urls>, tabs, storage, or nativeMessaging that were not explicitly authorized by the user.Google patched this vulnerability in Chrome 143.0.7499.192 (Windows/Linux) and 143.0.7499.192/.193 (Mac), released January 6, 2026. Microsoft released patches for Edge (Chromium-based) on January 9, 2026, as part of the January 2026 Patch Tuesday. Organizations should immediately update all Chrome and Edge installations to the latest available versions. As a temporary workaround, restrict users from installing unvetted Chrome extensions via enterprise policy, and consider disabling the Gemini Live side panel feature where not required. Monitor for suspicious extension installations and enforce extension allowlisting in managed environments (Chrome Releases, Microsoft MSRC).
Palo Alto Networks Unit 42 published a detailed technical report in March 2026 revealing the full scope of the vulnerability, specifically its ability to allow malicious extensions to hijack Chrome's Gemini Live AI panel and access cameras, microphones, and files — significantly elevating the perceived severity beyond the initial disclosure (Unit 42). Forbes covered the story with the headline "Google Chrome 143 Security Bypass — 3 Billion Users At Risk," driving broad public awareness. The Hacker News, ZDNet, The Register, Security Affairs, and GovInfoSecurity all published coverage, with The Register and ZDNet highlighting the Gemini AI panel hijacking angle as a novel and concerning attack surface. Security researchers on Reddit's r/netsec discussed a common architectural pattern across multiple Q1 2026 browser vulnerabilities, and the community broadly emphasized the risks of AI-integrated browser features expanding the attack surface for extensions.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."