logo

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI

ID: 813e7913-9ac9-5d4a-adff-4ba0acf37184

STIX ID: report--813e7913-9ac9-5d4a-adff-4ba0acf37184

Feed Name: CyberScoop

Threat Score
75/100

Date Published: 2026-05-08

Date Updated: 2026-05-22

Author: djohnson

...
...

The report describes a serious security flaw in Anthropic’s Claude Chrome extension discovered by LayerX: an extension API allowed unverified scripts and other extensions to send hidden instructions to the Claude agent, enabling privilege escalation across extensions. Researchers demonstrated proof-of-concept attacks that bypassed safety guardrails to exfiltrate Google Drive files, read and send Gmail messages, and access private GitHub repositories. LayerX disclosed the issue to Anthropic, which issued a partial fix, but researchers reported remaining scenarios where the agent could still be hijacked.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.