Claude Chrome Extension Flaw Lets Malicious Extensions Steal Gmail and Google Drive Data
ID: be401a53-aefd-5683-a03c-3a35b9859052
STIX ID: report--be401a53-aefd-5683-a03c-3a35b9859052
Feed Name: Cyber Press
Threat Score
*Executive summary:* A critical trust-boundary flaw in the Claude in Chrome extension (ClaudeBleed) allows any malicious Chrome extension to impersonate a trusted origin and send privileged runtime messages to Claude, enabling silent exfiltration of sensitive data from Gmail, Google Drive, and private GitHub repos; an attempted patch was quickly bypassed, and mitigations recommended include authenticated request tokens and restricting externally_connectable to explicit extension IDs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
