Google Chrome Gemini AI bug CVE-2026-0628 allowed extension script injection
Google Chrome's Gemini AI feature was found to have a big security bug.
The issue, called CVE-2026-0628, made it possible for shady browser extensions to inject scripts or HTML into a privileged page via a crafted Chrome Extension, putting your privacy and data at risk.
Versions of Chrome before 143.0.7499.192 were affected, and the flaw was disclosed by senior principal security researcher Gal Weizman from Palo Alto Networks's Unit 42 team.
Google patched vulnerability January 2026
Hackers could use this glitch to access things like your webcam or files, or even trick you with phishing attacks, all through the Gemini panel using the declarativeNetRequests API.
Google fixed the problem in January 2026 with a browser update, so if you haven't updated Chrome yet, now's definitely the time!
Keeping your browser up to date is still one of the easiest ways to stay safe online.