Google Chrome Gemini AI Vulnerability Exposes Users to Surveillance and Data Theft

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A high-severity vulnerability in Google Chrome's Gemini AI assistant allowed malicious browser extensions to exploit the AI panel's elevated privileges, enabling unauthorized access to users' cameras, microphones, local files, and sensitive data. Discovered by Palo Alto Networks' Unit 42, the flaw was patched by Google in January 2026.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system explicitly mentioned as the Gemini agentic AI feature in Google Chrome. The vulnerability allowed malicious extensions to exploit the AI system's permissions and perform unauthorized actions, directly leading to harms such as spying on users, stealing data, and phishing. These harms fall under injury to privacy and security of persons, which is a violation of rights and harm to individuals. Since the vulnerability was actively exploitable and caused realized harm, this qualifies as an AI Incident. The article also discusses broader security implications and mitigation efforts, but the primary focus is on the realized harm from the vulnerability exploitation.[AI generated]
AI principles
Privacy & data governanceRobustness & digital security

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Human or fundamental rights

Severity
AI incident

AI system task:
Interaction support/chatbots


Articles about this incident or hazard

Thumbnail Image

This high-severity Chrome Gemini vulnerability lets malicious extensions spy on your PC

2026-03-02
ZDNet
Why's our monitor labelling this an incident or hazard?
The event involves an AI system explicitly mentioned as the Gemini agentic AI feature in Google Chrome. The vulnerability allowed malicious extensions to exploit the AI system's permissions and perform unauthorized actions, directly leading to harms such as spying on users, stealing data, and phishing. These harms fall under injury to privacy and security of persons, which is a violation of rights and harm to individuals. Since the vulnerability was actively exploitable and caused realized harm, this qualifies as an AI Incident. The article also discusses broader security implications and mitigation efforts, but the primary focus is on the realized harm from the vulnerability exploitation.
Thumbnail Image

Google Chrome Patch Signals Need for Constant AI Browser Vigilance | PYMNTS.com

2026-03-02
PYMNTS.com
Why's our monitor labelling this an incident or hazard?
The article explicitly mentions an AI system (Google's Gemini AI assistant integrated into Chrome) and a security vulnerability that could have allowed malicious extensions to escalate privileges and access sensitive user data and device functions. Although the vulnerability was fixed before exploitation, the potential for harm was credible and directly linked to the AI system's design and use. Since no actual harm occurred but a plausible risk was present, this fits the definition of an AI Hazard rather than an AI Incident. The article also discusses broader concerns about AI browser security, reinforcing the potential for future incidents if such vulnerabilities are not managed.
Thumbnail Image

Bug in Google's Gemini AI Panel Opens Door to Hijacking

2026-03-02
Dark Reading
Why's our monitor labelling this an incident or hazard?
The event explicitly involves an AI system (Google's Gemini AI integrated into Chrome) whose malfunction (security flaw) could lead to serious harms such as privacy violations and unauthorized system access. The researchers demonstrated how malicious extensions could exploit the AI panel to hijack privileges, which directly relates to harm (privacy breach and system compromise). The vulnerability was active before being patched, indicating realized risk rather than just potential. Hence, it meets the criteria for an AI Incident due to direct harm linked to the AI system's use and malfunction.
Thumbnail Image

Chrome Gemini Vulnerability Lets Attackers Access Victims' Camera and Microphone Remotely

2026-03-02
Cyber Security News
Why's our monitor labelling this an incident or hazard?
The Gemini AI assistant is an AI system integrated into Chrome, providing multimodal AI capabilities with elevated permissions. The vulnerability exploited the AI system's privileged architecture, enabling attackers to hijack the AI panel and gain unauthorized access to sensitive hardware and data. This directly caused harms such as privacy violations, unauthorized surveillance, and data theft, which fall under injury or harm to persons and harm to property or communities. Since the harm is realized and directly linked to the AI system's malfunction and use, this qualifies as an AI Incident.