logo

Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

ID: 5f978115-8758-5236-9474-6a9eaba441a0

STIX ID: report--5f978115-8758-5236-9474-6a9eaba441a0

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-03-27

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical zero-click prompt-injection vulnerability in Anthropic’s Claude Chrome extension—caused by an overly broad *.claude.ai origin allowlist and a DOM XSS in an Arkose Labs CDN component—could be exploited via a hidden iframe to silently execute attacker-controlled prompts, enabling theft of Google OAuth tokens, access to Gmail/Drive, and exfiltration of chat history for over 3 million users; the issues were responsibly disclosed and patched in Jan–Feb 2026 (users should upgrade to version 1.0.41+).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.