logo

ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data

ID: 1ec95d71-883a-5305-9a0b-6d8b281c59b5

STIX ID: report--1ec95d71-883a-5305-9a0b-6d8b281c59b5

Feed Name: HackRead

Threat Score
72/100

Date Published: 2026-05-08

Date Updated: 2026-05-11

Author: Deeba Ahmed

...
...

**Executive Summary:** LayerX disclosed a critical origin-based vulnerability ("ClaudeBleed") in the Claude for Chrome extension that can allow untrusted web scripts or malicious extensions to command the assistant to access Google Drive, read and summarize Gmail, send emails, and delete evidence; researchers demonstrated practical exploitation techniques (approval looping, DOM manipulation) and showed that Anthropic's patch can be bypassed by forcing a privileged mode, leaving users exposed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.