Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data
ID: 10e80c5e-ef5e-5b97-8676-890c254b5dfd
STIX ID: report--10e80c5e-ef5e-5b97-8676-890c254b5dfd
Feed Name: cybersecurityNews.com
LayerX disclosed a trust-boundary vulnerability in the "Claude in Chrome" extension where reliance on origin-only checks in externally_connectable allows JavaScript (including from malicious, zero-permission extensions) to act with the extension's privileges. Researchers demonstrated a PoC that forges user approvals and manipulates UI semantics to steal Gmail, Google Drive, and private GitHub content without user interaction; Anthropic issued a partial fix but the fundamental externally_connectable handler and privileged-mode bypass remain unresolved, and LayerX recommends cryptographic sender validation, extension ID restrictions, and non-replayable approval tokens.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
