logo

Claude Chrome Extension Flaw Lets Malicious Extensions Steal Gmail and Google Drive Data

ID: be401a53-aefd-5683-a03c-3a35b9859052

STIX ID: report--be401a53-aefd-5683-a03c-3a35b9859052

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-12

Date Updated: 2026-05-12

Author: AnuPriya

...
...

*Executive summary:* A critical trust-boundary flaw in the Claude in Chrome extension (ClaudeBleed) allows any malicious Chrome extension to impersonate a trusted origin and send privileged runtime messages to Claude, enabling silent exfiltration of sensitive data from Gmail, Google Drive, and private GitHub repos; an attempted patch was quickly bypassed, and mitigations recommended include authenticated request tokens and restricting externally_connectable to explicit extension IDs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.