Are you still under the impression that your browser extensions are just harmless little helpers designed to block ads or save coupons? Do you really think your “private” AI assistant is keeping your secrets safe? Think again.
As of March 2026, the tech world is reeling from a discovery that proves we might be moving too fast for our own good. A high-severity security flaw, officially logged as CVE-2026-0628, has been uncovered in Google Chrome. This isn’t just another minor bug; it’s a direct hit on the Gemini Live AI assistant integration.
Joe Silverman, CEO of New York Computer Help, isn’t pulling any punches on this one. His “Hot Take”?
“AI features are being rushed into browsers. It’s a security nightmare. If you’re not patching your browser daily, you’re leaving the front door wide open.”
What Just Happened? The Unit 42 Discovery
The researchers over at Palo Alto Networks / Unit 42 recently dropped a bombshell report. They discovered that malicious extensions could essentially “hijack” a Gemini AI session. Because Google integrated Gemini so deeply into the Chrome architecture: specifically via a component internally known as “Glic”: they inadvertently created a side door for hackers.
Imagine an extension you downloaded to help with dark mode or tab management suddenly gaining the ability to see what your AI sees. That is exactly what CVE-2026-0628 allows.
The Technical “Oops”: How the Flaw Works
At the heart of this vulnerability is the declarativeNetRequest API. This is a common tool used by extensions (especially ad-blockers) to monitor and block network requests. Under normal circumstances, these extensions are restricted from messing with “privileged” browser pages: things like your settings or your passwords.
However, Unit 42 found that the WebView components used to embed the Gemini web app were “forgotten.” The security rules that usually keep extensions out of sensitive browser UI simply didn’t apply to the Gemini panel.
By injecting JavaScript into this unprotected panel, an attacker could take over the entire AI interface. Since Gemini has permission to see your screen and listen to your mic to “help” you, the attacker effectively inherits those same permissions.
Why This Is a “Security Nightmare”
Let’s get real about the stakes. This isn’t just about someone stealing your search history. If you use Gemini as your primary assistant, the hijacked session could allow an attacker to:
- Access Your Camera and Microphone: Since you likely gave Gemini permission to hear your voice commands, a compromised session turns your webcam into a surveillance tool.
- Capture Real-Time Screenshots: Gemini “sees” what is on your screen to provide context. Now, an attacker can see it, too: including your bank statements, private emails, and internal company data.
- Read Local Files: The AI assistant often has hooks into your file system to help you summarize documents. This flaw opens those directories to unauthorized “guests.”
- Phishing on Autopilot: The attacker can manipulate the Gemini interface to show you fake prompts, asking for your password or “re-authentication,” which looks perfectly legitimate because it’s happening inside a trusted Google panel.
If you’re running a business in NYC, this kind of exposure is catastrophic. This is why we advocate for robust Managed IT Support in NYC to ensure your fleet of computers isn’t running vulnerable, unpatched software.
The Problem with “Rushed” AI
Joe’s point about AI being rushed is backed by the data. In the race to beat competitors like Microsoft and OpenAI, browser developers are slapping AI into every corner of the user interface. When features are integrated this quickly, the security auditing process often can’t keep up.
We are seeing a trend where “convenience” features are prioritized over “hardened” security. Google Chrome version 143 was released with a fix, but how many users actually click that “Update” button the second it appears? In a world where a flaw like CVE-2026-0628 exists, waiting even 24 hours to patch is a massive gamble.
Are Mac Users Safe?
Don’t think for a second that your MacBook Pro makes you immune. Chrome is the most popular browser on macOS, and this vulnerability is cross-platform. Whether you’re on a Windows workstation or a high-end Mac, if you’re using Chrome with Gemini features enabled, you are at risk.
We often see clients at our shop who think their hardware security is enough, but software vulnerabilities like this bypass physical hardware protections entirely. If your system has been acting sluggish or you suspect an extension has gone rogue, it might be time for a professional Apple repair in NYC check-up to ensure your system integrity hasn’t been compromised by “ghost” extensions.
How to Protect Yourself Right Now
You don’t need a degree in cybersecurity to close this “front door.” Here is your immediate action plan:
- Update Chrome Immediately: Go to
Settings > About Chrome. If you aren’t on at least version 143, update and relaunch right now. - Audit Your Extensions: Be ruthless. If you haven’t used an extension in a month, delete it. Only keep extensions from developers you explicitly trust.
- Check Gemini Permissions: Review what permissions you’ve granted to the “Glic” or Gemini panel. If it doesn’t need your camera for your daily workflow, revoke it.
- Patch Daily: As Joe says, make it a habit. Don’t let your browser stay open for weeks at a time without a restart.
The Role of Professional Oversight
For many of our clients, managing these updates across twenty or fifty computers is a full-time job. That’s where things get messy. When one employee misses a patch, the entire network is vulnerable.
Imagine a scenario where a hijacked Gemini session leads to a ransomware attack on your server. Suddenly, you’re not just looking at a browser bug; you’re looking at a total business halt. If the worst happens and you lose access to your critical files, you’ll be looking for Data Recovery and Computer Repair faster than you can say “Gemini.”
A Forward-Looking Warning
The disclosure of CVE-2026-0628 by Palo Alto Networks is likely just the tip of the iceberg. As browsers become “AI-native,” the attack surface is growing exponentially. We are no longer just protecting a window to the internet; we are protecting a proactive assistant that has its hands in everything we do.
The “Hot Take” remains the same: AI is a powerful tool, but it’s currently a security wild west. You cannot trust that the software companies have thought of everything. You have to be your own first line of defense.
Stay updated, stay skeptical of your extensions, and for heaven’s sake, restart your browser. Your privacy depends on it.
Source Information:
This report is based on findings from Palo Alto Networks’ Unit 42 regarding CVE-2026-0628. For more technical details on the session hijacking mechanics, you can reference the Cyber Insider report here.
Category: News
Meta Description: Google Chrome’s Gemini AI assistant has a major security flaw (CVE-2026-0628). Learn how malicious extensions can hijack your camera, mic, and files: and how to stay safe.
Tags: Google Chrome, Gemini AI, Cybersecurity, CVE-2026-0628, Unit 42, Joe Silverman, NY Computer Help
Note: Some images in this article may be AI-generated.


