New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel

2026-03-05T13:44:49Z0723a281c0d6ed71ac0dddd826d1faab5260c00f1f3bf6556c55acda3310a1ee
CVE-2025-40538CVE-2026-0628CVE-2026-20127CVE-2026-21513CVE-2026-25108APT28Cisco SD-WANFileZenGeminiGoogle ChromeGoogle Cloud API keysMSHTMLNuGetPQCServ-USolarWindsWebViewblockchain C2botnetexploitextensionsmalwarenpmpatchpost-quantumprivilege escalationsupply-chainvulnerabilityzero-day

What happened

This collection is a security news roundup covering multiple high-impact vulnerabilities, active exploit campaigns, supply-chain abuses, and threat actor activity. Key highlights: a patched Chrome WebView/extension privilege-escalation bug (CVE-2026-0628) that could expose local files via the Gemini panel; a maximum-severity Cisco SD-WAN authentication-bypass zero-day (CVE-2026-20127) actively exploited since 2023; MSHTML vulnerability CVE-2026-21513 tied to APT28 exploitation; CISA-confirmed active exploitation of FileZen command-injection (CVE-2026-25108); and four critical Serv‑U RCE flaws,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
0723a281c0d6ed71ac0dddd826d1faab5260c00f1f3bf6556c55acda3310a1ee
Enrichment time
2026-03-05T13:44:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.