Palo Alto Networks’ Unit 42 disclosed CVE-2026-0628 on March 2, 2026, a high-severity flaw in the Gemini Live panel built into Google Chrome that let a malicious extension, even one with only basic permissions, hijack the panel through the browser’s declarativeNetRequest API. Exploiting the flaw allowed injected JavaScript to gain unauthorized access to a victim’s camera, microphone, local files, and screenshot capability without consent. Google fixed the vulnerability in early January 2026, before Unit 42’s public disclosure, and no in-the-wild exploitation was reported.