New Zero-Click Flaw in Claude Desktop Extensions, Anthropic Declines Fix
ID: 63a5bd12-ff4a-5a1e-9704-8d3c0dd4b558
STIX ID: report--63a5bd12-ff4a-5a1e-9704-8d3c0dd4b558
Feed Name: Infosecurity Magazine (News)
LayerX disclosed a critical remote code execution vulnerability in Anthropic's Claude Desktop Extensions (DXT) where MCP servers run without sandboxing and can autonomously execute instructions sourced from connectors (e.g., Google Calendar). A crafted calendar event can trigger a DXT to run arbitrary system commands with full host privileges; LayerX rated the issue CVSS 10.0 and estimated over 10,000 affected users, while Anthropic declined to fix it, arguing it falls outside their threat model.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
