logo

Claude Desktop Extensions 0-Click RCE Vulnerability Exposes 10,000+ Users to Remote Attacks

ID: 5bae8814-e63f-5b7a-b3af-96c4d8653c61

STIX ID: report--5bae8814-e63f-5b7a-b3af-96c4d8653c61

Feed Name: cybersecurityNews.com

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-21

Author: Guru Baran

...
...

**Zero-click RCE in Claude Desktop Extensions:** LayerX disclosed a critical architectural vulnerability (CVSS 10/10) in Claude Desktop Extensions where a malicious Google Calendar event can be interpreted by the model and cause a privileged local MCP extension to fetch and execute attacker code, resulting in full system compromise; researchers recommend disconnecting high-privilege local connectors from agents that ingest untrusted external data.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.