Claude Desktop Reportedly Adds Browser Access Bridge for Multiple Chromium-Based Browsers
ID: e8925f47-0ff6-5a68-966b-96f6c6795f33
STIX ID: report--e8925f47-0ff6-5a68-966b-96f6c6795f33
Feed Name: Cyber Press
A privacy researcher found that Anthropic’s Claude Desktop for macOS silently writes a com.anthropic.claude_browser_extension.json Native Messaging manifest into multiple Chromium-based browser support folders, creating a pre-authorized communication channel to a local executable that runs outside the browser sandbox. The persistent, hidden installation enables powerful actions (DOM access, session extraction, automated actions, screen recording) and could be abused if pre-authorized extensions are compromised or via prompt injection; organizations are advised to audit for the manifest and require opt-in controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
