WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges A security weakness in Anthropic’s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce. The issue was discovered by Manifold Security researcher Ax Sharma, who found that Claude for Chrome did not adequately distinguish between a genuine user interaction and a synthetic click generated through JavaScript. The attack does not allow an ordinary malicious website to take control of Claude, nor does it give an attacker the ability to submit arbitrary prompts. Instead, the attacker would first have to persuade the victim to install a separate browser extension with permission to run code on the claude.ai domain. Once installed, that extension could manipulate the page’s Document Object Model (DOM), insert an element containing one of Claude’s recognised workflow identifiers and programmatically generate a click. According to Manifold, Claude would then process the event as though the user had selected the workflow themselves. The potential consequences depend heavily on the user’s Claude configuration, the connected services available to the extension and whether sensitive operations require confirmation. The risk is greater when Claude’s optional “Act without asking” mode is enabled because supported operations may proceed without an additional approval step. Manifold said the issue remained reproducible in Claude for Chrome version 1.0.80, released on July 7, despite being reported to Anthropic in May. The researchers assigned the issue a CVSS score of 7.7 under the default approval configuration and 9.6 when automatic action is enabled. Those scores are Manifold’s assessment and do not appear to have been issued by Anthropic. Missing check allows synthetic clicks The weakness centres on the
WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges
Read the original article
linkedin.com →