logo

Claude Desktop changes app access settings for browsers you don't even have installed yet

ID: b89fe117-5565-5697-82a3-a9d44553978a

STIX ID: report--b89fe117-5565-5697-82a3-a9d44553978a

Feed Name: The Register (Security)

Threat Score
50/100

Date Published: 2026-04-20

Date Updated: 2026-04-26

Author: Thomas Claburn

...
...

Anthropic's Claude Desktop for macOS was found to write a Native Messaging manifest that pre-authorizes Chrome/Chromium extensions and registers across multiple browser install paths without user disclosure or opt-in, creating a persistent local bridge to a helper binary outside the browser sandbox; this expands the attack surface, may enable prompt-injection chains, and raises potential violations of EU ePrivacy rules and regulatory risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.