logo

AI Hijacked: Critical Claude Chrome Extension Flaw Allows Malicious Scripts to Control Your AI

ID: dedfa613-fccc-5d21-899d-a2ff38e3ebba

STIX ID: report--dedfa613-fccc-5d21-899d-a2ff38e3ebba

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-05-11

Date Updated: 2026-05-11

Author: Ddos

...
...

LayerX disclosed a critical vulnerability in Anthropic’s "Claude in Chrome" extension where unverified cross-extension messaging lets any installed extension hijack Claude, inject malicious instructions, and exfiltrate data or perform actions (e.g., steal Google Drive files, send emails, steal GitHub code). Researchers showed how UI manipulation can bypass Claude's policy enforcement, and although Anthropic provided a partial fix, the root cause remains unresolved, leaving the extension a potential enterprise data-exfiltration vector.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.