Malicious extensions could hijack Chrome's Gemini AI and expose data
A major security bug was found in Google Chrome's Gemini AI feature, making it possible for hackers to sneak into your private data.
Disclosed by senior principal security researcher Gal Weizman from Palo Alto Networks' Unit 42 team, this flaw let a malicious browser extension hijack Gemini, and the AI assistant may then take action without permission, including granting a cybercriminal access to webcams and microphones, taking screenshots, and accessing local files and directories; definitely not ideal for anyone who values privacy.
Chrome 143.0.7499.192 patched Gemini flaw
Google quickly rolled out a fix in January with Chrome version 143.0.7499.192, so if you haven't updated your browser yet, now's the time!
This issue is a good reminder to keep browsers up to date and treat AI-powered tools with extra caution: they can be awesome but also need strong security to keep your info safe.