logo

Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers

ID: f39f4acf-74c8-5b5a-886b-9424ef7d2b62

STIX ID: report--f39f4acf-74c8-5b5a-886b-9424ef7d2b62

Feed Name: cybersecurityNews.com

Threat Score
68/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Abinaya

...
...

### Executive Summary Privacy researcher Alexander Hanff discovered that Anthropic's Claude Desktop for macOS automatically drops a Native Messaging manifest (com.anthropic.claude_browser_extension.json) into the application support folders of up to seven Chromium-based browsers, pre-authorizing three Chrome extension IDs to invoke a helper binary. This silent, persistent installation occurs without user consent (even for browsers not installed) and rewrites manifests on launch, increasing attack surface and raising risks of out-of-sandbox execution and sensitive data exposure, though the report does not present evidence of active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.