NewsCVE-2026-0628 Chrome Gemini Live Hijack CVSS 8.8The Hacker News·high signalXBlueskyLinkedInCopy linkMalicious Chrome extensions could hijack Gemini Live panel for webcam, mic, file access via declarativeNetRequest APISourceSource pageThe Hacker News↳ Follow the threadPolicy dependency / Stack layerCherry Studio v2.0.9 unifies tool approval into one declarative policy and lets the provider catalog hot-update without an app releaseGitHubStack layer / Threat patternGoogle Cloud Shipped Gemini Enterprise for Financial Services With 50 Skills, 13 Connectors and a Partner Agent MarketplaceGoogle Cloud Blog (corroborated by PRNewswire, 2026-08-25 12:00)Policy dependency / Stack layerA vision paper separates access from control and argues AI concentrates software power rather than democratizing itarXiv 2608.24720 (submitted 2026-08-25)Policy dependency / Stack layerWebMCP-Phalanx blocks all 80 tool-description injections in a browser agent, then gets bypassed by a malicious tool name called before inspectionarXivPolicy dependency / Stack layerHalofy ships an open governance layer for agents with identity, policy, provenance, audit and signed erasureGitHubPolicy dependency / Threat patternAgno 3.0.1 caches tool schemas across runs and loads session history incrementally, so response time stops scaling with conversation lengthGitHub (agno-agi/agno)Stack layer / Threat patternTrojanized pantheon-agents wheels on PyPI ship a Bun-based credential stealer, GitHub source untouchedGitHub Advisory DatabaseStack layer / Threat patternClaude Code 2.1.247 Stops Subagents From Dying on a First-Call Model 404Claude Code Changelog