AI Hijacked: Critical Claude Chrome Extension Flaw Allows Malicious Scripts to Control Your AI
ID: dedfa613-fccc-5d21-899d-a2ff38e3ebba
STIX ID: report--dedfa613-fccc-5d21-899d-a2ff38e3ebba
Feed Name: securityonline.info
LayerX disclosed a critical vulnerability in Anthropic’s "Claude in Chrome" extension where unverified cross-extension messaging lets any installed extension hijack Claude, inject malicious instructions, and exfiltrate data or perform actions (e.g., steal Google Drive files, send emails, steal GitHub code). Researchers showed how UI manipulation can bypass Claude's policy enforcement, and although Anthropic provided a partial fix, the root cause remains unresolved, leaving the extension a potential enterprise data-exfiltration vector.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
