← All stories
● Covered by 3 sources · 3 reportsMedium impact

Claude for Chrome Vulnerability Exposes User Data to Rogue Extensions

🔄 Updated 77d ago — new reporting from BleepingComputer
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Claude for Chrome has a critical vulnerability.
  • Rogue extensions can access Gmail, Docs, Calendar, and more.
  • Current version 1.0.80 is unpatched as of July 14.
  • Issue stems from simulating fake user clicks.
  • Anthropic previously attempted to fix similar vulnerabilities.

Overview

A critical security flaw has been identified in the Claude for Chrome browser extension, developed by Anthropic. This vulnerability permits rogue browser extensions to simulate user clicks and trigger predefined tasks, thereby potentially exposing sensitive data.

Vulnerability Details

AI security firm Manifold discovered the flaw which allows malicious extensions to exploit Claude's features to access services such as Gmail, Google Docs, Google Calendar, and Salesforce. The vulnerability arises from Claude’s mechanism that initiates actions based on click events, without verifying their legitimacy.

The flaw persists in version 1.0.80 of Claude for Chrome, despite previous mitigations aimed at similar vulnerabilities like ClaudeBleed. The issue remains unpatched as of July 14.

Risk and Recommendations

The vulnerability is particularly concerning for users utilizing the 'Act without asking' mode, which allows tasks to proceed without prompts. Even in the default mode, rogue tasks only require minimal user interaction to be set in motion.

To mitigate risks, users are advised to disable the 'Act without asking' option and review extensions with data modification permissions on Claude.ai. This will re-enable the task approval step, albeit retaining the potential for forged clicks.

Why It Matters

The existence of such vulnerabilities underscores the need for rigorous security measures in popular browser extensions, particularly those with access to sensitive data spread across essential online services like email and document management. Ongoing diligence is necessary to safeguard user data against malicious actors in the evolving browser extension landscape.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

A flaw in the Claude Chrome extension permits malicious extensions to simulate user clicks, triggering AI workflows linked to services like Gmail and Salesforce. This vulnerability can expose sensitive user data and permissions, raising significant security concerns for Claude's users.

A vulnerability in Claude for Chrome allows rogue browser extensions to trigger tasks that access Gmail, Google Docs, and Calendar. Despite being partially mitigated in previous updates, Manifold Security found that the flaw persists in version 1.0.80, posing a significant security risk for users.

Manifold reports that two vulnerabilities in Claude for Chrome allow malicious extensions to read sensitive user data without consent. This indicates a significant security oversight by Anthropic, as the risks could expose Gmail, Google Docs, and calendar entries to attackers.