WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges
A security vulnerability in the Claude for Chrome extension allows malicious browser extensions to trigger AI workflows without user consent. This flaw could potentially expose sensitive data from connected services like Gmail or Salesforce if the user has enabled 'Act without asking' mode.
Why it matters
This highlights the security risks associated with browser extensions that have broad permissions and the potential for AI-integrated tools to be exploited by malicious software.
A security weakness in Anthropic’s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce.
The issue was discovered by Manifold Security researcher Ax Sharma, who found that Claude for Chrome did not adequately distinguish between a genuine user interaction and a synthetic click generated through JavaScript.
The attack does not allow an ordinary malicious website to take control of Claude, nor does it give an attacker the ability to submit arbitrary prompts. Instead, the attacker would first have to persuade the victim to install a separate browser extension with permission to run code on the claude.ai domain.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in