A significant vulnerability was recently found in Chrome’s Gemini Live AI assistant. It could have allowed malicious browser extensions to take over the AI panel and monitor users.
How the Hijack Worked
- The flaw: Researchers at Palo Alto Networks Unit 42 found that browser extensions with basic permissions could control the Gemini Live interface.
- Privilege escalation: An attacker could bypass security prompts to access a user’s [camera and microphone], take [screenshots] of active tabs, and read [local files] on the machine.
- Prompt injection: The vulnerability used hidden prompts in malicious websites. These prompts could trick the AI agent into executing commands for the attacker.
Current Status & Protection
- The patch: Google has fixed the issue in recent updates. Users should ensure their Chrome browser is up to date.
- Extension audit: Security experts warn that many users were recently tricked by fake AI extensions. Review and remove any suspicious or unfamiliar tools from your Chrome Extension Manager.