Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-20 · updated: 2026-09-20 · tags: [cve] · confidence: high · severity: high · affected_sectors: [global] · au_impact: false

Against Chrome, the researcher weakened security headers and redirected a JavaScript resource to execute code in the embedded Gemini web app's context, reaching Chrome's privileged AI component directly and seizing the ability to read local files, reach web content, take screenshots and potentially access the camera and microphone; Google assigned CVE-2026-0628 and paid US$7,000.

Attribute Detail
CVE CVE-2026-0628
CVSS 8.8 (CVSS 3.1, High)
Vendor / product Google Chrome (WebView tag, extension policy enforcement)
Reported 2026-09-20

NVD description

Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)