Claude for Chrome Flaw Lets Malicious Extensions Access Gmail and Google Docs
ID: 453ac829-efc7-50b1-9c3b-79e00274a735
STIX ID: report--453ac829-efc7-50b1-9c3b-79e00274a735
Feed Name: Cyber Press
Two unpatched vulnerabilities in Anthropic’s Claude for Chrome extension let any malicious browser extension trigger agentic tasks and access connected Gmail, Google Docs, and Calendar data without real user consent. The first is a missing event.isTrusted check on a click handler that permits synthetic clicks to invoke hardcoded privileged task IDs; the second is a side-panel URL parameter (skipPermissions=true) that flips the extension into privileged mode before showing a warning. Manifold reported the issues in May 2026 and later verified they remained in v1.0.80, and Anthropic’s reported fixes were incomplete across multiple releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
