bleeping-computer · Crawled Jul 16, 2026

Claude Chrome extension flaw lets malicious extensions trigger AI actions

Read original article ↗

AI Summary

A vulnerability in Anthropic's Claude for Chrome extension allows malicious browser extensions to trigger predefined AI workflows by simulating untrusted click events. The flaw arises because the extension fails to validate the Event.isTrusted property, enabling unauthorized execution of actions in connected services like Gmail, Google Docs, Calendar, and Salesforce. Although the issue requires a malicious extension already installed by the user, it can abuse Claude's authenticated access to sensitive platforms without additional user consent.

AI-extracted · verify before operational use

No entities or IoCs were extracted from this article.