Vulnerability intelligence
CVE-2026-0628
Google Chrome
Insufficient policy enforcement in WebView tag in Google Chrome prior to 143.0.7499.192 allowed an attacker who convinced a user to install a malicious extension to inject scripts or HTML into a privileged page via a crafted Chrome Extension. (Chromium security severity: High)
CVSS Score
—
Unrated
EPSS — Exploit Probability
6.6%
Riskier than 94% of all CVEs · checked 2026-09-16
Exploitation
Not in CISA KEV
KEV does not include every exploited vulnerability
Remediation
Patch available
Vendor fix published
7 articles across 6 outlets · first covered Mar 2, 2026 · latest Sep 16, 2026
Coverage timeline
-
Browser Extensions Hijacked Chrome and Edge AI Assistants in BragJack Attackswww.darkreading.com · Sep 16, 2026
-
Chrome Gemini side panel CVE-2026-0628 exposes extension abusewww.malwarebytes.com · Mar 3, 2026
-
Chrome patch stops extension hijack of Gemini Live, CVE-2026-0628securityaffairs.com · Mar 3, 2026
-
Chrome CVE-2026-0628 enables WebView abuse to access camera, micthehackernews.com · Mar 2, 2026
-
Chrome CVE-2026-0628 lets extensions hijack Gemini Live AIwww.securityweek.com · Mar 2, 2026
-
Google patches CVE-2026-0628 in Chrome Gemini AI panelwww.darkreading.com · Mar 2, 2026
-
Chrome Gemini CVE-2026-0628 lets extensions hijack the panelunit42.paloaltonetworks.com · Mar 2, 2026