Chrome Gemini vulnerability allowed malicious extensions to hijack AI and spy on users
A high-severity vulnerability in Google Chrome's Gemini AI feature let malicious browser extensions escalate privileges and access system resources like webcams, microphones, and local files. Discovered by Palo Alto Networks, CVE-2026-0628 was patched in January, but it highlights growing security risks of agentic AI integration in browsers.