A critical security flaw has been identified in the Claude for Chrome browser extension, developed by Anthropic. This vulnerability permits rogue browser extensions to simulate user clicks and trigger predefined tasks, thereby potentially exposing sensitive data.
AI security firm Manifold discovered the flaw which allows malicious extensions to exploit Claude's features to access services such as Gmail, Google Docs, Google Calendar, and Salesforce. The vulnerability arises from Claude’s mechanism that initiates actions based on click events, without verifying their legitimacy.
The flaw persists in version 1.0.80 of Claude for Chrome, despite previous mitigations aimed at similar vulnerabilities like ClaudeBleed. The issue remains unpatched as of July 14.
The vulnerability is particularly concerning for users utilizing the 'Act without asking' mode, which allows tasks to proceed without prompts. Even in the default mode, rogue tasks only require minimal user interaction to be set in motion.
To mitigate risks, users are advised to disable the 'Act without asking' option and review extensions with data modification permissions on Claude.ai. This will re-enable the task approval step, albeit retaining the potential for forged clicks.
The existence of such vulnerabilities underscores the need for rigorous security measures in popular browser extensions, particularly those with access to sensitive data spread across essential online services like email and document management. Ongoing diligence is necessary to safeguard user data against malicious actors in the evolving browser extension landscape.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
A flaw in the Claude Chrome extension permits malicious extensions to simulate user clicks, triggering AI workflows linked to services like Gmail and Salesforce. This vulnerability can expose sensitive user data and permissions, raising significant security concerns for Claude's users.
A vulnerability in Claude for Chrome allows rogue browser extensions to trigger tasks that access Gmail, Google Docs, and Calendar. Despite being partially mitigated in previous updates, Manifold Security found that the flaw persists in version 1.0.80, posing a significant security risk for users.
Manifold reports that two vulnerabilities in Claude for Chrome allow malicious extensions to read sensitive user data without consent. This indicates a significant security oversight by Anthropic, as the risks could expose Gmail, Google Docs, and calendar entries to attackers.