Security researchers uncovered a critical flaw allowing malicious extensions to hijack Chrome's Gemini AI panel.
“An extension influencing a website is expected. However, an extension influencing a component that is baked into the browser is a serious security risk.”— Gal Weizman, Unit 42 Researcher, Palo Alto Networks
8.8CVSS severity score
CVE-2026-0628Vulnerability ID
143.0.7499.192Patched Chrome version
Jan 2026Patch release date