• News In Brief
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • News In Brief
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview
No Result
View All Result
No Result
View All Result
Home AI

Palo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panel

SmartSolutionUser1 by SmartSolutionUser1
March 25, 2026
in AI
0
Palo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panel
76
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Unit 42 has identified and responsibly disclosed a high-severity vulnerability (CVE-2026-0628) affecting “Gemini Live in Chrome,” Google Chrome’s AI-powered side panel.

You might also like

Onix Deepens Strategic Collaboration with Google Cloud to Help Accelerate Enterprise-Scale Cloud, Data, and Agentic AI Transformation

4 in 5 Indian Firms Deploy AI Under Pressure, Security Gaps Persist – TrendAI

SiMa.ai Secures Strategic Investment from Micron to Scale High-Performance, Power-Efficient Physical AI

At a high level, the issue involved a privilege escalation or “privilege jump.” Chrome extensions typically operate within defined permission boundaries. However, Unit 42 found that a malicious extension could manipulate how the Gemini web app was loaded inside Chrome’s AI side panel — a browser environment that operates with higher privileges than a standard web tab.

Because the Gemini panel is treated as a trusted browser surface, influencing what loads inside it could allow an extension-controlled payload to execute in a more powerful context than the extension itself was granted.

How it worked: Privilege Escalation via AI Side Panels

The vulnerability allowed a malicious browser extension — even one with basic host permissions — to interfere with the Gemini Live side panel. Researchers found the extension could leverage Chrome’s request-modification capabilities to intercept and alter resources associated with the Gemini web application. This issue applied only when Gemini was accessed through the side panel, not a regular browser tab.

When loaded in the side panel, Gemini runs within a more privileged browser process, tightly integrated with browser features and granted enhanced capabilities that ordinary web pages do not have.

Due to how requests and content embedding were implemented, an extension permitted to interact with the Gemini domain could intercept and modify JavaScript resources before they were rendered in the panel. In effect, attacker-controlled code could be injected into content executing inside the panel’s higher-trust environment.

The extension itself did not gain new permissions. Instead, it manipulated the content pipeline feeding a privileged component. Because that component already had elevated capabilities, the injected code effectively “rode along” into a more powerful execution context — creating the privilege jump.

A successful exploit of CVE-2026-0628 could have enabled an attacker to:

  • Access local files and directories
  • Capture screenshots of browsing sessions
  • Activate camera and microphone capabilities without appropriate awareness
  • Execute phishing attacks within the trusted Gemini interface

The attack required no additional user interaction beyond installing a malicious extension and opening the Gemini panel.

Remediation and Protection

Palo Alto Networks notified Google on Oct. 23, 2025. Google confirmed the findings and released a fix in early January 2026.

Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks
Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks

Mr. Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks said, “Today’s agentic browsers can act on your behalf — researching, reasoning and taking action without direct user input. While this can deliver meaningful productivity gains, in the absence of enterprise-grade controls these tools can take autonomous actions beyond IT oversight. By inheriting a user’s browser session and accessing screens, files, cameras and microphones, agentic browsers can expand the attack surface through prompt manipulation and weakened web isolation, creating security and accountability gaps enterprises haven’t faced before.

The research highlights a broader architectural lesson: as AI becomes embedded into core browser components, strict isolation between extension-controlled content and privileged AI surfaces is essential to preserving the browser’s security model.

If you have an interesting Article / Report/case study to share, please get in touch with us at editors@roymediative.com roy@roymediative.com, 9811346846/9625243429.

Tags: Palo Alto NetworksPalo Alto Networks Unit 42 Uncovers Vulnerability in Google Chrome’s Gemini AI Panelsmart solutions worldUnit 42 Uncovers Vulnerability
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Onix Deepens Strategic Collaboration with Google Cloud to Help Accelerate Enterprise-Scale Cloud, Data, and Agentic AI Transformation

by SmartSolutionUser1
April 11, 2026
0
Onix Deepens Strategic Collaboration with Google Cloud to Help Accelerate Enterprise-Scale Cloud, Data, and Agentic AI Transformation

Onix, a leading Data and AI services-as-software company, announced a major expanded strategic collaboration with Google Cloud. Leveraging its proprietary Wingspan agentic AI and Data modernization platform, Onix...

Read moreDetails

4 in 5 Indian Firms Deploy AI Under Pressure, Security Gaps Persist – TrendAI

by SmartSolutionUser1
April 10, 2026
0
4 in 5 Indian Firms Deploy AI Under Pressure, Security Gaps Persist – TrendAI

TrendAI™ has published new global research revealing that organizations worldwide are pushing ahead with AI deployment despite known security and compliance risks. A new global study* of 3,700...

Read moreDetails

SiMa.ai Secures Strategic Investment from Micron to Scale High-Performance, Power-Efficient Physical AI

by SmartSolutionUser1
April 10, 2026
0
SiMa.ai Secures Strategic Investment from Micron to Scale High-Performance, Power-Efficient Physical AI

SiMa.ai, a leader in Physical AI, announced a strategic investment from Micron Technology, Inc., strengthening its ability to scale production-ready, high-performance Physical AI solutions for real-world intelligent systems....

Read moreDetails

AI&Beyond Launches ‘AI&Beyond Partner Circle’ to Scale AI Adoption Across Enterprises

by SmartSolutionUser1
April 9, 2026
0
AI&Beyond Launches ‘AI&Beyond Partner Circle’ to Scale AI Adoption Across Enterprises

AI&Beyond, India’s pioneering AI literacy company, today announced the launch of the AI&Beyond Partner Circle, a curated partnership programme designed to accelerate enterprise AI adoption through trusted networks...

Read moreDetails

AI, Cybersecurity, digital and data skills emerge as India’s most critical future capabilities – NIIT India Skills Gap Report

by SmartSolutionUser1
April 8, 2026
0
AI, Cybersecurity, digital and data skills emerge as India’s most critical future capabilities – NIIT India Skills Gap Report

NIIT Ltd., a leading Skills & Talent development corporation, launched the NIIT India Skills Gap Report 2026, a nationwide study conducted in partnership with YouGov. The survey, based...

Read moreDetails
Next Post
Akamai Guardicore Segmentation Transforms Zero Trust with New AI-Powered Capabilities

Akamai Guardicore Segmentation Transforms Zero Trust with New AI-Powered Capabilities

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Browse by Category

Browse by Category

Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

  • News In Brief
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

BROWSE BY TAG

Acquisition Agentic AI Agora AI Akamai AMD Aurionpro automation Cloudflare CloudKeeper Coforge CrowdStrike Cybersecurity Databricks Fortinet Gartner GenAI Genesys Google Cloud Honeywell IBM Infosys Kaspersky Kramer LTIMindtree Microsoft New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Qualcomm Seqrite ServiceNow SiMa.ai smart solutions world smartsolutionsworld smart solutions world latest news Software Tata Communications Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • News In Brief
  • AI
  • Education
  • Pro AV
  • Case Study
  • Interview

© 2024 NCN - Premium news & magazine by NCN.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?