Claude for Chrome flaw could let rogue extensions access your Gmail
ID: 14ebd215-c0f0-593b-a90c-aef68e5762bc
STIX ID: report--14ebd215-c0f0-593b-a90c-aef68e5762bc
Feed Name: Malwarebytes Blog
Researchers disclosed a privilege/agency bypass in the Claude for Chrome extension ("ClaudeBleed") where a malicious browser extension or script can masquerade as the user and instruct Claude to access sensitive services (Gmail, Google Drive, GitHub) or send/manipulate messages and documents; Anthropic applied partial patches but the core handoff and allowlist weaknesses remain, and users are advised to disable "Act without asking," remove untrusted extensions, and limit assistant access to sensitive accounts until a comprehensive fix is released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
