logo

Claude for Chrome Flaw Puts Gmail at Risk From Rogue Extensions

ID: 1b799e48-c684-5de0-b781-b5e33f18bd95

STIX ID: report--1b799e48-c684-5de0-b781-b5e33f18bd95

Feed Name: TechRepublic Security

Threat Score
75/100

Date Published: 2026-07-16

Date Updated: 2026-07-20

Author: Kezia Jungco

...
...

Anthropic's Claude for Chrome contains flaws that let a malicious extension synthesize user clicks and potentially bypass approval prompts (notably when "Act without asking" or the ?skipPermissions=true state is present), allowing an attacker to trigger a limited set of predefined tasks that can access Gmail, Google Docs, and Google Calendar. Manifold Security reproduced the bypass, rated the issue high (CVSS 7.7) and critical (CVSS 9.6) with unattended mode enabled, and recommended rejecting synthetic clicks, avoiding URL-controlled privilege changes, and strengthening internal authentication; organizations should disable unattended mode and limit accounts or disable the beta until a full fix is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.