Skip to main content
  1. Home
  2. Computing
  3. News

Gemini panel in Chrome left the doors open for hackers, and you must update ASAP

You should update your browser now to avoid Chrome's Gemini security hole.

Add as a preferred source on Google
Running Google Gemini experience on iOS.
Google

A recently disclosed vulnerability in Google’s Gemini AI panel could have allowed hackers to hijack the feature and access sensitive data on a user’s device. Researchers at Palo Alto Networks’ Unit 42 first discovered the flaw, which is labeled as CVE-2026-0628.

According to the report, the issue stemmed from how Chrome handled permissions for the Gemini side panel. This is a browser feature that integrates Google’s AI assistant directly into the browsing experience. The discovered vulnerability could have enabled malicious browser extensions with basic permissions to inject code into the Gemini panel.

Since the Gemini panel runs with elevated privileges in Chrome, attackers could exploit the flaw and gain access to systems that are normally restricted.

What hackers could’ve done with the exploit

Once the Gemini panel is hijacked, the attacker can potentially execute code with powerful system-level privileges. Researchers showed that this would enable several dangerous actions, such as:

  • Accessing the camera and microphone without user consent
  • Taking screenshots of any webpage
  • Reading local files and directories from the OS
  • Running malicious scripts inside the Gemini interface

The good news: Google already patched it

The vulnerability was initially disclosed to Google in October 2025, and the company released a fix in January 2026 after reproducing the issue internally. While the flaw is now patched, security researchers warn that the incident highlights a broader issue, which is that AI-powered browser features introduce new security risks because they require deeper access to the system.

Recommended Videos

So for the everyday user, the takeaway is simple. Update Chrome immediately to make sure you’re on a version that includes the security fix.

Vikhyaat Vivek
Vikhyaat Vivek is a tech journalist and reviewer with seven years of experience covering consumer hardware, with a focus on…
Claude’s Sonnet 5 is built to do more on its own and cost you less
Better than its predecessor, nearly as good as the flagship, and meaningfully cheaper than both.
Art, Floral Design, Graphics

Every major AI lab is racing to prove its models can work autonomously with minimal hand-holding; we’re now seeing pricing emerge as the next battleground. 

Anthropic just fired its latest shot, Claude Sonnet 5, a model the company says performs nearly as well as its flagship Opus 4.8 at a fraction of the cost.

Read more
Apple Creator Studio adds AI tools across Final Cut Pro, Logic Pro and Pixelmator Pro
Final Cut Pro gets AI captions, Auto Mask and better Pixelmator Pro workflows in Creator Studio update
Computer Hardware, Electronics, Hardware

Apple has introduced a major update to Apple Creator Studio, adding new AI features, deeper Pixelmator Pro integration, and workflow upgrades across Final Cut Pro, Logic Pro, Keynote, Pages, Numbers, Motion, Compressor, Freeform, and Final Cut Camera.

The update makes Creator Studio more useful across Mac, iPad, and iPhone, especially for people who move between video editing, image editing, presentations, documents, spreadsheets, and music production.

Read more
AI browsers like Perplexity Comet can be tricked into spilling your password through BioShocking exploit
Six AI browsers were found leaking saved passwords and many of them haven't fixed it yet.
MacBook Air in hand, Comet browser loaded—let’s see what Perplexity’s AI can really do

Security researchers just found a strange way to trick AI browsers into handing over your passwords. They managed to trick AI browser agents into exposing sensitive data like saved passwords, session cookies, and private tokens by disguising the theft as part of a harmless "game."

The technique is called BioShocking, named after the popular video game BioShock, where a brainwashed character is manipulated into believing a false reality. Once an AI browser falls for the same trick, it stops following its own safety rules entirely.

Read more