logo

Claude Desktop Reportedly Adds Browser Access Bridge for Multiple Chromium-Based Browsers

ID: e8925f47-0ff6-5a68-966b-96f6c6795f33

STIX ID: report--e8925f47-0ff6-5a68-966b-96f6c6795f33

Feed Name: Cyber Press

Threat Score
65/100

Date Published: 2026-04-24

Date Updated: 2026-04-25

Author: AnuPriya

...
...

A privacy researcher found that Anthropic’s Claude Desktop for macOS silently writes a com.anthropic.claude_browser_extension.json Native Messaging manifest into multiple Chromium-based browser support folders, creating a pre-authorized communication channel to a local executable that runs outside the browser sandbox. The persistent, hidden installation enables powerful actions (DOM access, session extraction, automated actions, screen recording) and could be abused if pre-authorized extensions are compromised or via prompt injection; organizations are advised to audit for the manifest and require opt-in controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.