[{"data":1,"prerenderedAt":92},["ShallowReactive",2],{"story-124317-en":3},{"id":4,"slug":5,"slugs":5,"currentSlug":5,"title":6,"subtitle":7,"coverImagesSmall":8,"coverImages":9,"content":20,"questions":21,"relatedArticles":43,"body_color":90,"card_color":91},"124317",null,"Chrome Gemini AI Vulnerability Exposes E-Commerce Sellers to Account Hijacking | CVE-2026-0628 Security Risk","- Critical privilege escalation flaw patched January 2025 threatens seller credentials, business files, and customer communications across Amazon, Shopify, and eBay platforms",[],[10,11,12,13,14,15,16,17,18,19],"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt62ea066bfc2ba78d/69a570ad37a8be5be476868d/chrome_QubixStudio_shutterstock.jpg?width=1280&auto=webp&quality=80&format=jpg&disable=upscale","https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSVqQqtncTq4mbTaX27P6rKcpwnIKje_UgELsrXAJCRcchMMe1djj3kYb2HFz58wC8eUIEsK-eYgDRFLWzUihJyVT532Of2kcZs1Do9-fMZmO4PwGpXV1mqgo0Ia1T2zAOFoCXLYxbAMpC7WqI8Or8GzuaIqILGsLzAAfYX_y_-nnZ0Z4fNlFMzk0Bo60/s1600/Juniper%20Networks%20PTX%20Flaw%20(17)%20(1).webp","https://www.pymnts.com/wp-content/uploads/2023/12/Google-Chrome.jpg?w=457","https://www.securityweek.com/wp-content/uploads/2023/04/Chrome-Zero-Day-exploits.jpg","https://www.findarticles.com/wp-content/uploads/2026/03/chrome_gemini_bug_lets_malicious_extensions_spy_on_edited_1772464689.png","https://www.zdnet.com/a/img/resize/66c10200743084b2d0707aa8822fa577ec242fc9/2025/03/18/8c41994b-bf7b-4d2b-80f4-3a29468c3f20/new-report-finds-chatbots-can-steal-passwords-from-chrome.jpg?auto=webp&width=1280","https://cyberinsider.com/wp-content/uploads/2026/03/New-Chrome-flaw-lets-attackers-hijack-Gemini-AI-researchers-warn.jpg","https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/AdobeStock_799983387.jpeg","https://i1.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhjRhFuyKtHsG3IsuSdVHK8OJXLcn34YoO1BV2lb0ACl8hunoa20DogDTD1B38ONlpyueyKY99LzY2HhZ1KDRX2k58IAfHWr2t-ryOIwwpZQKu7DsKyCzz4UvtdDfEJHVbMr9w0qvLhFR_YbojBrI-7vruHXlXH16LueH8NSIJGmv2gFi1URBOMNBQy2xhu/s1600/Chrome%20Gemini%20Vulnerability%20Lets%20Attackers%20Access%20Victims%E2%80%99%20Camera%20and%20Microphone%20Remotely%20%281%29.webp?w=1600&resize=1600,900&ssl=1","https://i2.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBLWOZZ_FwCeZLjyP-b-LZPDCGcWPA610SoSjI9cEEAhqOFn4VTSAe86JBieePTujv13N6VrBfhh6ApiBekn5k5UoB3RnezgzDs6Eq75w2DduCdbGQfboOT76_D1iPIy_kepDYl1z2jA7fJ5x2yNSZF9lNxWMnD6h1PG-MOIIYjeITnIo7Pb0FTz0d2Z0b/s16000/Chrome%20Gemini%20Vulnerability1.webp?w=1600&resize=1600,900&ssl=1","**CRITICAL SECURITY ALERT FOR E-COMMERCE SELLERS**: Google patched a high-severity vulnerability (CVE-2026-0628) in Chrome's Gemini AI panel discovered by Palo Alto Networks Unit 42 in October 2024 and fixed in early January 2025. The flaw allowed malicious browser extensions with basic permissions to escalate privileges and access sensitive system resources without user consent. For cross-border e-commerce sellers managing operations through Chrome, this vulnerability created direct threats to business continuity: attackers could hijack authenticated sessions to Amazon Seller Central, Shopify admin dashboards, and eBay Seller Hub; capture screenshots of sensitive business files including supplier contracts, pricing spreadsheets, and customer data; access webcam/microphone during video calls with suppliers or customers; and execute phishing attacks through the trusted Gemini interface to steal seller credentials.\n\n**THE TECHNICAL ATTACK VECTOR**: The vulnerability exploited Chrome's declarativeNetRequests API—legitimately used by extensions like AdBlock to filter requests—to inject malicious JavaScript into the privileged Gemini panel. Unlike ordinary website interception, compromising the Gemini panel granted attackers elevated browser-level capabilities normally restricted from extensions. Critically, these actions required no user interaction beyond clicking the Gemini button to activate the panel. Palo Alto Networks researcher Gal Weizman emphasized that \"the vulnerability put any user of the new Gemini feature in Chrome at risk of system compromise if they had installed a malicious extension,\" with amplified risks in business environments where sellers manage multiple marketplace accounts.\n\n**OPERATIONAL IMPACT FOR SELLERS**: This vulnerability represents a fundamental breach of Chrome's security architecture that directly threatens e-commerce operations. Sellers relying on Chrome for managing inventory across multiple platforms faced risks including: credential theft through phishing attacks displayed in the trusted Gemini panel (potentially compromising Amazon FBA accounts, Shopify stores, and eBay seller accounts simultaneously); unauthorized access to sensitive business files stored locally (supplier agreements, pricing strategies, customer lists); potential compromise of webcam/microphone during video calls with suppliers, customers, or logistics partners; and data exfiltration of local files and directories containing business-critical information. The vulnerability affected all Chrome users with extensions installed until the January 2025 patch, creating a window of exposure for sellers who hadn't updated their browsers.\n\n**AGENTIC AI SECURITY PARADIGM SHIFT**: This incident reveals emerging security challenges as browsers increasingly integrate agentic AI capabilities. Unlike traditional browsers that display content, AI-powered browsers actively execute complex, multistep operations with elevated system access. This expanded functionality creates a \"new and widened attack surface\" that traditional network and endpoint controls were never designed to monitor. Anupam Upadhyaya from Palo Alto Networks notes that agentic AI can inherit authenticated browser sessions and perform privileged actions within enterprise applications, potentially modifying data or triggering workflows—a critical concern for sellers using AI-assisted tools for pricing optimization, inventory management, and customer service automation. The incident underscores how new features can inadvertently reintroduce classic vulnerabilities like privilege escalation and cross-site scripting when implemented within high-privilege contexts.",[22,25,28,31,34,37,40],{"title":23,"answer":24,"author":5,"avatar":5,"time":5},"How should e-commerce teams manage browser security across multiple team members and devices?","Organizations should implement centralized browser security policies: (1) Enforce automatic Chrome updates across all devices through your IT infrastructure; (2) Maintain an approved extensions whitelist—only allow extensions that are essential for business operations and regularly reviewed; (3) Implement real-time visibility into extension behavior and user navigation through enterprise security tools like Palo Alto Networks' Prisma Browser, which is specifically designed to prevent extension-based attacks; (4) Require two-factor authentication on all marketplace accounts and enforce strong password policies; (5) Conduct quarterly security audits of installed extensions and user access patterns; (6) Provide security training to team members about extension risks and phishing attacks; (7) Segregate sensitive operations—consider using dedicated devices or browsers for accessing marketplace accounts, supplier systems, and payment processors. For cross-border sellers with distributed teams, this means treating browsers as primary attack surfaces requiring the same security controls as your company's core infrastructure.",{"title":26,"answer":27,"author":5,"avatar":5,"time":5},"How does this vulnerability differ from typical phishing attacks that target e-commerce sellers?","Traditional phishing attacks rely on tricking sellers into clicking malicious links or entering credentials on fake websites. This vulnerability is fundamentally different because it operates at the browser level with elevated system access, requiring no user deception. Attackers could display phishing content directly within the trusted Gemini panel—which carries inherent credibility as a legitimate Google feature—making sellers far more likely to trust and interact with malicious content. Additionally, the vulnerability enabled attackers to access authenticated sessions automatically, meaning they could perform actions on your behalf without needing your credentials. This represents a new attack surface that traditional email security and password managers don't adequately address, which is why Palo Alto Networks emphasizes treating browsers as primary attack surfaces requiring continuous monitoring.",{"title":29,"answer":30,"author":5,"avatar":5,"time":5},"What is the timeline for when this vulnerability affected sellers and when protection was available?","The vulnerability was discovered in October 2024 by Palo Alto Networks Unit 42 researchers and responsibly disclosed to Google on October 23, 2024. Google confirmed the vulnerability and released a patch on January 5, 2026, before public disclosure. This means sellers were at risk for approximately 2.5 months between discovery and patch release. However, the vulnerability remained a threat to any seller who hadn't updated Chrome to the latest version after January 5, 2026. For sellers who delayed updates, the exposure window extended beyond the patch release date. This incident underscores the importance of enabling automatic Chrome updates and treating security patches as critical rather than optional maintenance.",{"title":32,"answer":33,"author":5,"avatar":5,"time":5},"Which browser extensions pose the highest risk for e-commerce sellers?","Extensions with network request interception capabilities—like AdBlock, uBlock Origin, and similar content filtering tools—posed the highest risk because they legitimately use Chrome's declarativeNetRequests API, which was exploited in this vulnerability. However, the threat extends beyond obvious security tools: any extension with basic permissions could potentially be compromised. Palo Alto Networks noted that malicious extensions deployed to browser web stores have grown significantly in recent years, and legitimate extensions have been hijacked or sold to threat actors who pushed malicious updates to already-installed endpoints. For sellers, this means even trusted extensions from your browser's web store could become attack vectors. Review your installed extensions immediately and remove any that are outdated, unused, or from unfamiliar developers.",{"title":35,"answer":36,"author":5,"avatar":5,"time":5},"What immediate steps should I take to protect my e-commerce business from this vulnerability?","First, update Chrome to the latest version (patched January 5, 2026 or later) immediately—this is non-negotiable. Second, audit your installed extensions: remove any that are outdated, unused, or from unfamiliar developers, particularly those with network request permissions. Third, enable two-factor authentication on all marketplace accounts (Amazon Seller Central, Shopify, eBay) and change passwords for any accounts accessed through Chrome. Fourth, review your account activity logs for suspicious changes—check Amazon Seller Central's login history, Shopify's audit logs, and eBay's account activity for unauthorized access. Fifth, consider using alternative browsers (Firefox, Safari, Edge) for accessing sensitive business tools until you've fully audited your Chrome extensions. Finally, implement real-time visibility into extension behavior by monitoring which extensions access your data and network traffic.",{"title":38,"answer":39,"author":5,"avatar":5,"time":5},"How does the CVE-2026-0628 vulnerability specifically threaten my Amazon Seller Central account?","The vulnerability allowed malicious extensions to inject JavaScript into Chrome's Gemini panel, which could intercept your authenticated Amazon Seller Central session and perform unauthorized actions. Attackers could modify inventory listings, change pricing, access confidential sales reports, or trigger refunds without your knowledge. The threat was particularly severe because the attack required no user interaction beyond clicking the Gemini button—your existing login credentials were automatically inherited by the compromised panel. All sellers using Chrome with extensions installed were at risk until Google's January 2025 patch. Immediately verify your Amazon account activity logs for any suspicious changes and enable two-factor authentication if not already active.",{"title":41,"answer":42,"author":5,"avatar":5,"time":5},"What specific actions could attackers perform after hijacking the Gemini panel?","Once attackers compromised the Gemini panel through malicious extensions, they could: (1) Access your camera and microphone for silent surveillance during supplier or customer video calls, potentially capturing sensitive business discussions; (2) Capture screenshots of any HTTPS website you visited, including confidential pricing spreadsheets, supplier agreements, or customer data stored in cloud tools like Google Sheets or Dropbox; (3) Read local files and directories from your operating system, extracting business-critical documents stored on your computer; (4) Execute phishing attacks through the trusted Gemini interface, which carries inherent credibility that standalone phishing pages lack, potentially stealing credentials for multiple marketplace accounts simultaneously. The research demonstrated all these capabilities were accessible without additional user interaction beyond the initial Gemini panel activation.",[44,49,53,58,62,66,70,74,78,82,86],{"id":45,"title":46,"source":47,"logo":18,"time":48},517579,"Chrome Gemini Vulnerability Lets Attackers Access Victims’ Camera and Microphone Remotely","https://gbhackers.com/chrome-gemini-vulnerability/","4D AGO",{"id":50,"title":51,"source":52,"logo":19,"time":48},517652,"Chrome Gemini Vulnerability Lets Attackers Access Victims' Camera and Microphone Remotely","https://cybersecuritynews.com/chrome-gemini-vulnerability/",{"id":54,"title":55,"source":56,"logo":11,"time":57},517578,"Critical Flaw in Google Chrome Gemini Exposes Users’ Camera and Microphone to Hackers","https://cyberpress.org/critical-flaw-in-google-chrome-gemini/","3D AGO",{"id":59,"title":60,"source":61,"logo":14,"time":48},517583,"Chrome Gemini Bug Lets Malicious Extensions Spy on PCs","https://www.findarticles.com/chrome-gemini-bug-lets-malicious-extensions-spy-on-pcs/",{"id":63,"title":64,"source":65,"logo":13,"time":48},517582,"Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant","https://www.securityweek.com/vulnerability-allowed-hijacking-chromes-gemini-live-ai-assistant/",{"id":67,"title":68,"source":69,"logo":5,"time":48},517651,"New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel","https://thehackernews.com/2026/03/new-chrome-vulnerability-let-malicious.html",{"id":71,"title":72,"source":73,"logo":15,"time":48},517584,"This high-severity Chrome Gemini vulnerability lets malicious extensions spy on your PC","https://www.zdnet.com/article/gemini-live-chrome-bug-hijacks-ai/",{"id":75,"title":76,"source":77,"logo":17,"time":48},517650,"Taming Agentic Browsers: Vulnerability in Chrome Allowed Extensions to Hijack New Gemini Panel","https://unit42.paloaltonetworks.com/gemini-live-in-chrome-hijacking/",{"id":79,"title":80,"source":81,"logo":10,"time":48},517649,"Bug in Google's Gemini AI Panel Opens Door to Hijacking","https://www.darkreading.com/endpoint-security/bug-google-gemini-ai-panel-hijacking",{"id":83,"title":84,"source":85,"logo":12,"time":48},517581,"Google Chrome Patch Signals Need for Constant AI Browser Vigilance","https://www.pymnts.com/cybersecurity/2026/google-chrome-patch-signals-need-for-constant-ai-browser-vigilance/",{"id":87,"title":88,"source":89,"logo":16,"time":48},517580,"Chrome Vulnerability Could Let Attackers Hijack Gemini AI Sessions","https://cyberinsider.com/chrome-vulnerability-could-let-attackers-hijack-gemini-ai-sessions/","#fcdfaaff","#fcdfaa4d",1772883064212]