New Chrome Vulnerability Let Malicious Extensions Escalate Privileges via Gemini Panel

2026-03-05T13:45:59Z53ea04d266e2c34aed2bb5d11f27de1ebb9ba7852c9b49be9b91a86b1ad932e6
CVE-2025-40538CVE-2026-0628CVE-2026-20127CVE-2026-21513CVE-2026-25108APT28CISAChromeCisco SD-WANGeminiGo moduleGoogle Cloud API keysMSHTMLNuGetactive-exploitationblockchain-C2botnetmalicious-packagesnpmsoftware-supply-chainsupply-chainvulnerabilityzero-day

What happened

A large set of security stories covering multiple high-impact vulnerabilities, active exploit campaigns, and supply-chain abuse. Notable technical issues include a Chrome WebView/’Gemini panel’ privilege-escalation bug (CVE-2026-0628, CVSS 8.8) and an MSHTML feature-bypass exploited by APT28 (CVE-2026-21513, CVSS 8.8). A maximum-severity Cisco SD‑WAN zero-day (CVE-2026-20127, CVSS 10.0) has been actively exploited since 2023. CISA confirmed active exploitation of FileZen OS command injection (CVE-2026-25108, CVSS 8.7). SolarWinds patched multiple critical Serv‑U flaws (including CVE-2025-40538

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
53ea04d266e2c34aed2bb5d11f27de1ebb9ba7852c9b49be9b91a86b1ad932e6
Enrichment time
2026-03-05T13:45:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.