Claude for Chrome Flaw Puts Gmail at Risk From Rogue Extensions
ID: 1b799e48-c684-5de0-b781-b5e33f18bd95
STIX ID: report--1b799e48-c684-5de0-b781-b5e33f18bd95
Feed Name: TechRepublic Security
Anthropic's Claude for Chrome contains flaws that let a malicious extension synthesize user clicks and potentially bypass approval prompts (notably when "Act without asking" or the ?skipPermissions=true state is present), allowing an attacker to trigger a limited set of predefined tasks that can access Gmail, Google Docs, and Google Calendar. Manifold Security reproduced the bypass, rated the issue high (CVSS 7.7) and critical (CVSS 9.6) with unattended mode enabled, and recommended rejecting synthetic clicks, avoiding URL-controlled privilege changes, and strengthening internal authentication; organizations should disable unattended mode and limit accounts or disable the beta until a full fix is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
