New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel
2026-03-05T13:44:49Z•0723a281c0d6ed71ac0dddd826d1faab5260c00f1f3bf6556c55acda3310a1ee
CVE-2025-40538CVE-2026-0628CVE-2026-20127CVE-2026-21513CVE-2026-25108APT28Cisco SD-WANFileZenGeminiGoogle ChromeGoogle Cloud API keysMSHTMLNuGetPQCServ-USolarWindsWebViewblockchain C2botnetexploitextensionsmalwarenpmpatchpost-quantumprivilege escalationsupply-chainvulnerabilityzero-day
What happened
This collection is a security news roundup covering multiple high-impact vulnerabilities, active exploit campaigns, supply-chain abuses, and threat actor activity. Key highlights: a patched Chrome WebView/extension privilege-escalation bug (CVE-2026-0628) that could expose local files via the Gemini panel; a maximum-severity Cisco SD-WAN authentication-bypass zero-day (CVE-2026-20127) actively exploited since 2023; MSHTML vulnerability CVE-2026-21513 tied to APT28 exploitation; CISA-confirmed active exploitation of FileZen command-injection (CVE-2026-25108); and four critical Serv‑U RCE flaws,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 0723a281c0d6ed71ac0dddd826d1faab5260c00f1f3bf6556c55acda3310a1ee
- Enrichment time
- 2026-03-05T13:44:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.