Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

New Chrome vulnerability lets extensions exploit Gemini panel for malicious gains

Mar 2, 2026 | Threat Intelligence Research

High-Severity Vulnerability in Chrome’s Gemini Feature Exposes Users to Risk

TL;DR
A critical vulnerability, CVE-2026-0628, was discovered in Google’s Gemini feature within Chrome, allowing malicious extensions to exploit the browser and gain unauthorized access to local resources. Palo Alto Networks reported this issue and assisted Google in issuing a fix to mitigate the risk prior to public disclosure.

Main Analysis
Palo Alto Networks identified a high-severity security flaw in Chrome’s Gemini, a newly integrated AI feature, which could enable attackers to leverage malicious browser extensions for extensive control over a user’s environment. The vulnerability allows an extension with minimal permissions to hijack the Gemini panel and execute unauthorized commands, resulting in privilege escalation. Such actions might include accessing the device’s camera and microphone, reading local files, and capturing screenshots without the user’s knowledge or consent.

The vulnerability lies in the design of the Gemini panel, which provides enhanced permissions not typically available to standard extensions. By utilizing the declarativeNetRequests API, malicious actors could inject JavaScript into the Gemini application when it is loaded through this specific panel, effectively circumventing the browser’s security model that normally isolates extensions from accessing privileged browser components. The existence of this flaw emphasizes the growing security challenges presented by modern web browsers incorporating AI functionalities.

While Google has addressed the vulnerability, organizations should be aware of the expanded attack surface created by such features. The transition toward AI-enabled browsers introduces new risks where conventional browsing security measures may fall short. It is imperative for users and enterprises employing Chrome’s Gemini feature to understand the implications and take proactive measures against potential exploitation through less privileged extensions, especially given the recent uptick in malicious browser extensions.

Defensive Context
Organizations using Chrome’s Gemini feature should be particularly vigilant as this vulnerability highlights a broader attack surface associated with the integration of AI capabilities within browsers. Enterprises that heavily rely on browser extensions for functionality could face significant risks if these extensions are malicious or compromised. Users not utilizing the Gemini feature, or those with strict extension management policies in place, may find themselves less impacted by this specific vulnerability.

Why This Matters
The risk posed by this vulnerability extends to organizations handling sensitive data or utilizing Chrome for communication and project management. The potential for unauthorized access to local files and devices creates a significant threat to both individual privacy and organizational data integrity, particularly in environments where trust in browser components is assumed.

Defender Considerations
Affected users should focus on managing and monitoring installed extensions, especially those interacting with AI-integrated features. Ensuring that extensions are obtained from trusted sources and routinely auditing extension permissions will be vital in mitigating the risks associated with extension-based attacks that could exploit the aforementioned vulnerability.

Indicators of Compromise (IOCs)
The specific CVE ID associated with this vulnerability is CVE-2026-0628. No additional IOCs were provided in the article.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles