Chrome Gemini bug could let extensions access data, Google patched
Technology
A serious bug was found in Chrome's Gemini AI that could let shady browser extensions sneak into private parts of your browser and grab your data.
The flaw, CVE-2026-0628, spotted by senior principal security researcher Gal Weizman from Palo Alto Networks's Unit 42 team, affects Chrome versions before 143.0.7499.192.
If you have not updated Chrome lately, now is the time. Google patched this back in January 2026.
Attackers trick users with fake extensions
Attackers could trick people into installing fake extensions, which then injected harmful code behind the scenes.
This bug is a reminder: only add extensions you trust and keep your browser up to date to stay safe online.
Even cool new AI features like Gemini need solid security!