logo

Claude’s Chrome Extension Vulnerability Allows Malicious Extensions to Steal Gmail and Drive Data

ID: 10e80c5e-ef5e-5b97-8676-890c254b5dfd

STIX ID: report--10e80c5e-ef5e-5b97-8676-890c254b5dfd

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: Abinaya

...
...

LayerX disclosed a trust-boundary vulnerability in the "Claude in Chrome" extension where reliance on origin-only checks in externally_connectable allows JavaScript (including from malicious, zero-permission extensions) to act with the extension's privileges. Researchers demonstrated a PoC that forges user approvals and manipulates UI semantics to steal Gmail, Google Drive, and private GitHub content without user interaction; Anthropic issued a partial fix but the fundamental externally_connectable handler and privileged-mode bypass remain unresolved, and LayerX recommends cryptographic sender validation, extension ID restrictions, and non-replayable approval tokens.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.