logo

Claude Chrome extension flaw lets malicious extensions trigger AI actions

ID: 4513938d-0a8e-5b13-811c-de4ee2fceb50

STIX ID: report--4513938d-0a8e-5b13-811c-de4ee2fceb50

Feed Name: Bleeping Computer

Threat Score
60/100

Date Published: 2026-07-16

Date Updated: 2026-07-16

Author: Lawrence Abrams

...
...

A security researcher found that the Anthropic Claude Chrome extension accepts JavaScript-generated click events without checking Event.isTrusted, allowing a malicious browser extension (if installed by a user) to trigger nine predefined Claude workflows that interact with services like Gmail, Google Docs, Google Calendar, and Salesforce. The issue is limited to those built-in tasks (not arbitrary prompt injection), was reported to Anthropic and acknowledged, and remained reproducible in version 1.0.80 as of July 7; a second informational finding (an internal skipPermissions=true parameter) was also disclosed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.