Urja Daily
No Result
View All Result
  • News
  • Renewable
    • Solar
    • Rooftop
    • Floating Solar
    • Module
    • Wind
    • Hydrogen
    • Biomass
    • Tenders
    • Sustainibility
  • Storage
  • E-Mobility
  • Battery
  • Smart City
  • Power
    • Smart Grid
    • Microgrid
    • Off-Grid
  • Editor’s Pick
    • Articles
    • In Talks
    • E-MAG
    • Market Research
  • On-demand Webinars
  • More
    • Events
    • Contact Us
    • Subscribe
  • News
  • Renewable
    • Solar
    • Rooftop
    • Floating Solar
    • Module
    • Wind
    • Hydrogen
    • Biomass
    • Tenders
    • Sustainibility
  • Storage
  • E-Mobility
  • Battery
  • Smart City
  • Power
    • Smart Grid
    • Microgrid
    • Off-Grid
  • Editor’s Pick
    • Articles
    • In Talks
    • E-MAG
    • Market Research
  • On-demand Webinars
  • More
    • Events
    • Contact Us
    • Subscribe
No Result
View All Result
Urja Daily
No Result
View All Result
Home News

Palo Alto Networks Flags Security Flaw in Chrome’s Gemini AI Panel

Google confirmed the findings and released a fix in early January 2026

Palak by Palak
March 11, 2026
in News
Reading Time: 3 mins read
0
Palo Alto Networks
Share on FacebookShare on TwitterShare on Linkedin

Unit 42 has identified and responsibly disclosed a high-severity vulnerability (CVE-2026-0628) affecting “Gemini Live in Chrome,” Google Chrome’s AI-powered side panel.

At a high level, the issue involved a privilege escalation or “privilege jump.” Chrome extensions typically operate within defined permission boundaries. However, Unit 42 found that a malicious extension could manipulate how the Gemini web app was loaded inside Chrome’s AI side panel — a browser environment that operates with higher privileges than a standard web tab.

RELATED POSTS

FPT Enters The Top Three of Europe’s Certified High-Voltage Battery Producers With TÜV SÜD Recognition 

Gruner’s CBG Plant Sets Asia Record with 23.5 TPD Output, Achieves 120% of Design Capacity at Satna

Because the Gemini panel is treated as a trusted browser surface, influencing what loads inside it could allow an extension-controlled payload to execute in a more powerful context than the extension itself was granted.

How it worked: Privilege Escalation via AI Side Panels

The vulnerability allowed a malicious browser extension — even one with basic host permissions — to interfere with the Gemini Live side panel. Researchers found the extension could leverage Chrome’s request-modification capabilities to intercept and alter resources associated with the Gemini web application. This issue applied only when Gemini was accessed through the side panel, not a regular browser tab.

When loaded in the side panel, Gemini runs within a more privileged browser process, tightly integrated with browser features and granted enhanced capabilities that ordinary web pages do not have.

Due to how requests and content embedding were implemented, an extension permitted to interact with the Gemini domain could intercept and modify JavaScript resources before they were rendered in the panel. In effect, attacker-controlled code could be injected into content executing inside the panel’s higher-trust environment.

The extension itself did not gain new permissions. Instead, it manipulated the content pipeline feeding a privileged component. Because that component already had elevated capabilities, the injected code effectively “rode along” into a more powerful execution context — creating the privilege jump.

A successful exploit of CVE-2026-0628 could have enabled an attacker to:

  • Access local files and directories
  • Capture screenshots of browsing sessions
  • Activate camera and microphone capabilities without appropriate awareness
  • Execute phishing attacks within the trusted Gemini interface

The attack required no additional user interaction beyond installing a malicious extension and opening the Gemini panel.

Remediation and Protection

Palo Alto Networks notified Google on Oct. 23, 2025. Google confirmed the findings and released a fix in early January 2026.

Anupam Upadhyaya, SVP, Product Management, Prisma SASE, Palo Alto Networks, said, “Today’s agentic browsers can act on your behalf — researching, reasoning and taking action without direct user input. While this can deliver meaningful productivity gains, in the absence of enterprise-grade controls these tools can take autonomous actions beyond IT oversight. By inheriting a user’s browser session and accessing screens, files, cameras and microphones, agentic browsers can expand the attack surface through prompt manipulation and weakened web isolation, creating security and accountability gaps enterprises haven’t faced before.

The research highlights a broader architectural lesson: as AI becomes embedded into core browser components, strict isolation between extension-controlled content and privileged AI surfaces is essential to preserving the browser’s security model.

Tags: AI PanelGooglePalo AltoSecurity
ShareTweetShare
Palak

Palak

Related Posts

FPT TUVSUDV

FPT Enters The Top Three of Europe’s Certified High-Voltage Battery Producers With TÜV SÜD Recognition 

by Urja Daily
June 23, 2026
0

FPT, the Iveco Group brand dedicated to the design, production, and sale of low-environmental impact powertrains, has obtained certification in...

Utkarsh Gupta

Gruner’s CBG Plant Sets Asia Record with 23.5 TPD Output, Achieves 120% of Design Capacity at Satna

by Urja Daily
June 23, 2026
0

Satna, Madhya Pradesh: Gruner Renewable Energy, the flagship company of the Gruner Group and one of World's fastest-growing Technology + Engineering,...

VinFast India

VinFast India, Tata Capital Join Hands for Dealer Financing

by Palak
June 20, 2026
0

Gurugram, Haryana, India - VinFast Auto India, a subsidiary of the global EV brand VinFast, has signed a Memorandum of...

Amit sethi

Securing India’s Roads

by Palak
June 17, 2026
0

India's automotive sector is accelerating toward a connected, electrified future, with millions of vehicles now equipped with electronic control units...

Comau

Comau and Omron Robotics Target Electronics and Medical Manufacturing Automation

by Palak
June 17, 2026
0

COMAU and OMRON Robotics collaborate to accelerate advanced industrial automation across high-growth manufacturing sectorsPartnership combines complementary robotics, control, and software...

Next Post
Cargill

Cargill Unveils New Food Innovations at AAHAR 2026

Hygge Energy

Hygge Energy, Atria Renewable Join Hands for Rooftop Solar and P2P Energy Trading

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED

FPT TUVSUDV

FPT Enters The Top Three of Europe’s Certified High-Voltage Battery Producers With TÜV SÜD Recognition 

June 23, 2026
FPT

FPT And Green Power Systems Help Boost Algeria’s Powdered Milk Production

June 23, 2026

MOST VIEWED

  • Solar

    When the Sun Began Paying the Electricity Bills: The Story of PM Surya Ghar Muft Bijli Yojana

    0 shares
    Share 0 Tweet 0
  • India’s Emerging Polysilicon Manufacturing Ecosystem: Opportunities and Challenges

    0 shares
    Share 0 Tweet 0
  • KP Group & PP Savani University Launches Urjanoor Scholarship

    0 shares
    Share 0 Tweet 0
  • Xpeng Selects u‑blox F9 Centimeter-level Multi-Band GNSS Technology for P7 Smart EV

    0 shares
    Share 0 Tweet 0
  • How proper refurbishment can extend life of pre-owned bikes in India?

    0 shares
    Share 0 Tweet 0

FPT Enters The Top Three of Europe’s Certified High-Voltage Battery Producers With TÜV SÜD Recognition 

FPT And Green Power Systems Help Boost Algeria’s Powdered Milk Production

Gruner’s CBG Plant Sets Asia Record with 23.5 TPD Output, Achieves 120% of Design Capacity at Satna

Integrals Power Validates Sustainably Produced Iron Phosphate Precursor and LFP Cathode Material in Cell Level at University of St Andrews

Power Transmission is the Foundation of Economic Growth

VinFast India, Tata Capital Join Hands for Dealer Financing

Latest Magazine

© 2016 – 2025 TechZone Print Media | All Rights Reserved

  • About Us
  • Contact Us
No Result
View All Result
  • News
  • Renewable
    • Solar
    • Rooftop
    • Floating Solar
    • Module
    • Wind
    • Hydrogen
    • Biomass
    • Tenders
    • Sustainibility
  • Storage
  • E-Mobility
  • Battery
  • Smart City
  • Power
    • Smart Grid
    • Microgrid
    • Off-Grid
  • Editor’s Pick
    • Articles
    • In Talks
    • E-MAG
    • Market Research
  • On-demand Webinars
  • More
    • Events
    • Contact Us
    • Subscribe

© 2016 - 2025 TechZone Print Media | All Rights Reserved