Researchers Warn of Data Exposure Risks in Claude Chrome Extension
ID: 68b5e25b-3d40-557b-b775-2ad7d054999c
STIX ID: report--68b5e25b-3d40-557b-b775-2ad7d054999c
Feed Name: HackRead
Threat Score
Zenity Labs' analysis of Anthropic's Claude Chrome extension warns that the extension remains persistently logged in and can act using users' credentials, enabling attacks like indirect prompt injection and JavaScript execution that can expose OAuth tokens, perform actions in services (e.g., Google Drive, Slack), and facilitate lateral movement; researchers demonstrated proof-of-concept abuses and noted that built-in mitigations like "Ask before acting" are insufficient.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
