The Ghost in the Browser: Is Claude Desktop Clandestinely Installing a Surveillance Bridge?
ID: 9b000086-5557-5ca1-8eb8-eb4704842ad4
STIX ID: report--9b000086-5557-5ca1-8eb8-eb4704842ad4
Feed Name: securityonline.info
A security researcher found that Claude Desktop silently installs a native messaging bridge by writing pre-authorized JSON manifests into multiple Chromium-based browsers; this bridge allows designated browser extensions to communicate with local executables and perform browser automation, access authenticated sessions and DOM content, and record sessions — all without user consent or an opt-out. The report highlights forced bundling across seven Chromium browsers, persistent manifest rewriting, opaque pre-authorized extension identities, and the resulting privacy and exfiltration risks; mitigation requires uninstalling the Claude desktop client.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
