Claude Desktop Reportedly Adds Browser Access Bridge for Chromium Browsers
ID: 7f021bcf-56cf-5a61-a47f-267fdba44a45
STIX ID: report--7f021bcf-56cf-5a61-a47f-267fdba44a45
Feed Name: GBHackers
A researcher found that Anthropic’s Claude Desktop for macOS automatically installs a Native Messaging manifest (com.anthropic.claude_browser_extension.json) into the application support folders of multiple Chromium-based browsers, creating a persistent, pre-authorized bridge that lets three extension IDs launch a local executable (chrome-native-host) outside the browser sandbox. This bridge enables powerful browser automation (reading DOM, extracting structured data, sharing authenticated sessions, form filling, background screen recording) and is rewritten on each launch, bypasses user consent, and significantly expands local attack surface—raising risks from prompt-injection, extension compromise, or supply-chain attacks. Organizations are advised to audit for the manifest file and Anthropic is urged to switch to an explicit opt-in model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
