logo

Flaw in Anthropic Claude Extensions Can Lead to RCE in Google Calendar: LayerX

ID: e8b0b6ff-50b2-587a-b1ec-95c7ce8f015c

STIX ID: report--e8b0b6ff-50b2-587a-b1ec-95c7ce8f015c

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-02-09

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

LayerX researchers disclosed a proof-of-concept vulnerability in Anthropic’s Claude Desktop Extensions (MCP) that allows a calendar event combined with a generic prompt (e.g., “take care of it”) to be autonomously chained to a privileged local MCP server and achieve zero-click remote code execution. Because Claude Desktop Extensions run unsandboxed with full system privileges, this flow can lead to full system compromise; the issue reportedly affects over 10,000 active users and ~50 extensions, and Anthropic declined to fix the behavior, noting the tools require user installation and permission configuration.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.