logo

Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website

ID: d90e29ba-d09d-5e33-8ded-255fea2334d1

STIX ID: report--d90e29ba-d09d-5e33-8ded-255fea2334d1

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-03-26

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Researchers disclosed a vulnerability called "ShadowPrompt" in Anthropic's Claude Chrome extension where an overly permissive origin allowlist plus a DOM-based XSS in an Arkose Labs CAPTCHA on a-cdn.claude.ai allowed any website to silently inject prompts into the assistant without user interaction; successful exploitation could leak access tokens, expose conversation history, or let attackers act on users' behalf. Anthropic patched the extension (v1.0.41) to enforce exact-origin checks after responsible disclosure on December 27, 2025, and Arkose Labs fixed the XSS on February 19, 2026.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.