logo

Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

ID: d53f388a-47a2-5253-9664-ba850a99355a

STIX ID: report--d53f388a-47a2-5253-9664-ba850a99355a

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-14

Date Updated: 2026-07-15

Author: [email protected] (The Hacker News)

...
...

Manifold and other researchers found two related vulnerabilities in the Claude for Chrome extension that allow a malicious extension or script with DOM access to forge a click (no event.isTrusted check) and/or load a side-panel URL that disables permission prompts, enabling silent reads of Gmail, Docs, and Calendar and automated actions; the issues were reported in May and remain present in v1.0.80 as of July, with no CVE or public patch noted.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.