Chrome Gemini AI flaw CVE-2026-0628 could let extensions access webcam
Heads up, Chrome users: a major security bug was just discovered in the Gemini AI feature.
This flaw (CVE-2026-0628) could let sketchy browser extensions inject scripts or HTML into a privileged page or the new Gemini panel browser component and even access things like your webcam or files without you knowing.
If your Chrome isn't updated to version 143.0.7499.192/.193 on Windows and macOS stable channels (143.0.7499.192 for Linux), it's time to hit that update button.
Google rolled out January 2026 fix
The bug was spotted by senior principal security researcher Gal Weizman from Palo Alto Networks's Unit 42 team and quietly reported to Google last October.
Google rolled out a fix in January 2026 for Windows, macOS, and Linux users (Windows and macOS: 143.0.7499.192/.193; Linux: 143.0.7499.192).
Updating now keeps your data safe and helps block these kinds of privacy risks before they become a bigger problem.