PT-2026-1549 · Google+2 · Google Chrome+2
Gal Weizman
·
Published
2026-01-06
·
Updated
2026-05-05
·
CVE-2026-0628
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 143.0.7499.192
Description
Insufficient policy enforcement in the
WebView tag allows a remote attacker to inject scripts or HTML into privileged pages via a crafted Chrome extension. This issue can be exploited if a user is convinced to install a malicious extension. Specifically, the flaw allows extensions to intercept traffic and inject JavaScript into the Gemini AI side panel, which operates in a highly privileged context. This leads to privilege escalation, enabling the attacker to silently activate the webcam and microphone, capture screenshots, read local files, and inject fake messages into the Gemini interface.Recommendations
Update Google Chrome to version 143.0.7499.192 or later.
Restrict extension installation policies via enterprise policies or user education to prevent untrusted extensions from being added.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Google Chrome
Red Os