logo

Claude for Chrome Flaw Lets Malicious Extensions Access Gmail and Google Docs

ID: 453ac829-efc7-50b1-9c3b-79e00274a735

STIX ID: report--453ac829-efc7-50b1-9c3b-79e00274a735

Feed Name: Cyber Press

Threat Score
78/100

Date Published: 2026-07-15

Date Updated: 2026-07-15

Author: Tamilselvan

...
...

Two unpatched vulnerabilities in Anthropic’s Claude for Chrome extension let any malicious browser extension trigger agentic tasks and access connected Gmail, Google Docs, and Calendar data without real user consent. The first is a missing event.isTrusted check on a click handler that permits synthetic clicks to invoke hardcoded privileged task IDs; the second is a side-panel URL parameter (skipPermissions=true) that flips the extension into privileged mode before showing a warning. Manifold reported the issues in May 2026 and later verified they remained in v1.0.80, and Anthropic’s reported fixes were incomplete across multiple releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.