PT-2026-1549 · Google+2 · Google Chrome+2
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 143.0.7499.192
Description
Insufficient policy enforcement in the
WebView tag allows a remote attacker to inject arbitrary scripts or HTML into privileged pages if a user is convinced to install a malicious Chrome extension. This flaw can be exploited via the Gemini AI side panel, which operates with high privileges. Successful exploitation enables privilege escalation, allowing the attacker to silently activate the webcam and microphone, take screenshots, and read local files from the system. The issue stems from a failure in the isolation layers when integrating AI features that require broad system access.Recommendations
Update Google Chrome to version 143.0.7499.192 or later.
Restrict the installation of untrusted extensions through enterprise policies or user education.
Exploit
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Google Chrome
Red Os