PT-2026-1549 · Google+2 · Google Chrome+2

·

CVE-2026-0628

·

Published

2026-01-06

·

Updated

2026-09-24

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 143.0.7499.192
Description Insufficient policy enforcement in the WebView tag allows a remote attacker to inject arbitrary scripts or HTML into privileged pages if a user is convinced to install a malicious Chrome extension. This flaw can be exploited via the Gemini AI side panel, which operates with high privileges. Successful exploitation enables privilege escalation, allowing the attacker to silently activate the webcam and microphone, take screenshots, and read local files from the system. The issue stems from a failure in the isolation layers when integrating AI features that require broad system access.
Recommendations Update Google Chrome to version 143.0.7499.192 or later. Restrict the installation of untrusted extensions through enterprise policies or user education.

Exploit

Fix

LPE

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-00887
CVE-2026-0628
DSA-6097-1
OPENSUSE-SU-2026:10016-1
OPENSUSE-SU-2026:20020-1

Affected Products

Debian
Google Chrome
Red Os