• News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

Palo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panel

SmartSolutionUser1 by SmartSolutionUser1
March 25, 2026
in AI
0
Palo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panel
76
SHARES
1.3k
VIEWS
Share on FacebookShare on Twitter

Unit 42 has identified and responsibly disclosed a high-severity vulnerability (CVE-2026-0628) affecting “Gemini Live in Chrome,” Google Chrome’s AI-powered side panel.

You might also like

Altimetrik Named to Constellation Research Shortlists for AI Services and Digital Transformation Services

Alteryx Launches New AI Capabilities to Bring Governed Analytics Anywhere Work Happens

India’s enterprise AI investment surges 119% but only 22% of Indian enterprises have the governance to match their AI ambition – ServiceNow

At a high level, the issue involved a privilege escalation or “privilege jump.” Chrome extensions typically operate within defined permission boundaries. However, Unit 42 found that a malicious extension could manipulate how the Gemini web app was loaded inside Chrome’s AI side panel — a browser environment that operates with higher privileges than a standard web tab.

Because the Gemini panel is treated as a trusted browser surface, influencing what loads inside it could allow an extension-controlled payload to execute in a more powerful context than the extension itself was granted.

How it worked: Privilege Escalation via AI Side Panels

The vulnerability allowed a malicious browser extension — even one with basic host permissions — to interfere with the Gemini Live side panel. Researchers found the extension could leverage Chrome’s request-modification capabilities to intercept and alter resources associated with the Gemini web application. This issue applied only when Gemini was accessed through the side panel, not a regular browser tab.

When loaded in the side panel, Gemini runs within a more privileged browser process, tightly integrated with browser features and granted enhanced capabilities that ordinary web pages do not have.

Due to how requests and content embedding were implemented, an extension permitted to interact with the Gemini domain could intercept and modify JavaScript resources before they were rendered in the panel. In effect, attacker-controlled code could be injected into content executing inside the panel’s higher-trust environment.

The extension itself did not gain new permissions. Instead, it manipulated the content pipeline feeding a privileged component. Because that component already had elevated capabilities, the injected code effectively “rode along” into a more powerful execution context — creating the privilege jump.

A successful exploit of CVE-2026-0628 could have enabled an attacker to:

  • Access local files and directories
  • Capture screenshots of browsing sessions
  • Activate camera and microphone capabilities without appropriate awareness
  • Execute phishing attacks within the trusted Gemini interface

The attack required no additional user interaction beyond installing a malicious extension and opening the Gemini panel.

Remediation and Protection

Palo Alto Networks notified Google on Oct. 23, 2025. Google confirmed the findings and released a fix in early January 2026.

Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks
Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks

Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks said, “Today’s agentic browsers can act on your behalf — researching, reasoning and taking action without direct user input. While this can deliver meaningful productivity gains, in the absence of enterprise-grade controls these tools can take autonomous actions beyond IT oversight. By inheriting a user’s browser session and accessing screens, files, cameras and microphones, agentic browsers can expand the attack surface through prompt manipulation and weakened web isolation, creating security and accountability gaps enterprises haven’t faced before.

The research highlights a broader architectural lesson: as AI becomes embedded into core browser components, strict isolation between extension-controlled content and privileged AI surfaces is essential to preserving the browser’s security model.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com roy@roymediative.com, 9811346846/9625243429.

Tags: Palo Alto NetworksPalo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panelsmart solutions worldUnit 42 Uncovers Vulnerability
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Altimetrik Named to Constellation Research Shortlists for AI Services and Digital Transformation Services

by SmartSolutionUser1
September 12, 2026
0
Altimetrik Named to Constellation Research Shortlists for AI Services and Digital Transformation Services

Altimetrik, an AI engineering company, has been named to Q3 2026 Constellation Research ShortLists™ for AI Services: Global and Digital Transformation Services (DTX): Global. The AI Services ShortList...

Read moreDetails

Alteryx Launches New AI Capabilities to Bring Governed Analytics Anywhere Work Happens

by SmartSolutionUser1
September 12, 2026
0
Alteryx Launches New AI Capabilities to Bring Governed Analytics Anywhere Work Happens

Alteryx, the agenticanalytics and automation company, today announced new AI capabilities across Alteryx One, its unified AI-powered analytics platform that brings together data preparation, analytics, automation and AI...

Read moreDetails

India’s enterprise AI investment surges 119% but only 22% of Indian enterprises have the governance to match their AI ambition – ServiceNow

by SmartSolutionUser1
September 11, 2026
0
India’s enterprise AI investment surges 119% but only 22% of Indian enterprises have the governance to match their AI ambition – ServiceNow

India is entering a defining phase of its AI journey. Enterprise AI investment grew 119% in a single year above the global average of 110%, according to the...

Read moreDetails

Comviva announces Kalyanasundaram Sivasubramaniam to lead the DigiTech Business, Accelerating Platform-Led Growth and AI Transformation

by SmartSolutionUser1
September 10, 2026
0
Comviva announces Kalyanasundaram Sivasubramaniam to lead the DigiTech Business, Accelerating Platform-Led Growth and AI Transformation

Comviva, a global leader in digital transformation solutions, announced the appointment of Kalyanasundaram Sivasubramaniam as Product Unit Head for its DigiTech business. In this role, he will lead...

Read moreDetails

New Research Highlights How Persistent and Growing Data Is Reshaping AI Infrastructure Economics – WD

by SmartSolutionUser1
September 10, 2026
0
New Research Highlights How Persistent and Growing Data Is Reshaping AI Infrastructure Economics – WD

The AI infrastructure conversation has largely been defined by compute. But new global research from IDC reveals another critical factor organizations must address as they scale AI: data...

Read moreDetails
Next Post
Akamai Guardicore Segmentation Transforms Zero Trust with New AI-Powered Capabilities

Akamai Guardicore Segmentation Transforms Zero Trust with New AI-Powered Capabilities

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Agentic AI AI AI-powered Akamai AMD CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner Google Cloud HCLTech Honeywell IBM India Infosys Kaspersky Keysight Kramer Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite ServiceNow SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Solutions Sophos Tata Communications Tech Mahindra Technology Tenable UiPath Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • Awards nights
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Not enough quota to unlock this post
Unlock left : 0
Are you sure want to cancel subscription?