logo

Researcher claims Claude Desktop installs “spyware” on macOS

ID: 0138034f-de6b-5e89-ae62-aba7af434014

STIX ID: report--0138034f-de6b-5e89-ae62-aba7af434014

Feed Name: Malwarebytes Blog

Threat Score
45/100

Date Published: 2026-04-22

Date Updated: 2026-04-28

...
...

Researcher analysis found that Claude Desktop (com.anthropic.claudefordesktop) on macOS drops a Native Messaging host manifest into multiple Chromium-based browser profiles (including profiles for browsers not installed), pre-authorizing extension IDs and creating a local, user-privilege bridge that could enable session access, DOM reading, form filling and other browser automation; the behavior expands attack surface, is not documented in detail by Anthropic, and has been replicated on macOS though evidence of active abuse is not provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.