10K Claude Desktop Users Exposed by Zero-Click Vulnerability
ID: 3b6c068f-895f-5969-b80b-37db684b3509
STIX ID: report--3b6c068f-895f-5969-b80b-37db684b3509
Feed Name: TechRepublic Security
**Executive summary:** A newly disclosed zero-click remote code execution vulnerability in Anthropic's Claude Desktop Extensions and its Model Context Protocol (MCP) can allow a malicious Google Calendar event to cause unsandboxed, full‑privileged desktop extensions to download and run attacker code when the user issues a vague prompt; LayerX demonstrated a proof‑of‑concept and assigned a CVSS score of 10.0, recommending disabling high‑privilege extensions, restricting agent execution of local commands, enforcing least privilege, and applying endpoint and network controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
