logo

Claude for Chrome flaw could let rogue extensions access your Gmail

ID: 14ebd215-c0f0-593b-a90c-aef68e5762bc

STIX ID: report--14ebd215-c0f0-593b-a90c-aef68e5762bc

Feed Name: Malwarebytes Blog

Threat Score
65/100

Date Published: 2026-07-15

Date Updated: 2026-07-16

...
...

Researchers disclosed a privilege/agency bypass in the Claude for Chrome extension ("ClaudeBleed") where a malicious browser extension or script can masquerade as the user and instruct Claude to access sensitive services (Gmail, Google Drive, GitHub) or send/manipulate messages and documents; Anthropic applied partial patches but the core handoff and allowlist weaknesses remain, and users are advised to disable "Act without asking," remove untrusted extensions, and limit assistant access to sensitive accounts until a comprehensive fix is released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.