Researchers say Anthropic's Claude for Chrome extension still has flaws that can let a malicious browser extension trigger Claude to act as the user and access sensitive Google account data. Manifold says the issues remain in version 1.0.80 despite eight releases since disclosure in May 2026. The bugs involve forged click events for pre-approved tasks and a side-panel URL parameter that can force Claude into its 'Act without asking' autonomous mode, extending concerns from the earlier ClaudeBleed issue.
Why it matters: People using Claude for Chrome, especially with 'Act without asking' enabled, could have email, documents, and calendar data exposed without a real approval click. Until Anthropic ships a full fix, users should review installed extensions, disable unnecessary ones, and avoid autonomous mode for sensitive accounts.
Lawrence Abrams
2026.07.16
97% relevant
This is the same underlying event: security flaws in Anthropic's Claude for Chrome extension that let a malicious browser extension abuse Claude's access to connected services. This source adds concrete detail on the click-simulation mechanism, the use of untrusted synthetic events, the affected built-in workflows including Salesforce actions, and the separate skipPermissions=true finding.
Eduard Kovacs
2026.07.14
100% relevant
This article establishes a distinct ongoing vulnerability story around Anthropic's Claude for Chrome extension, with new reporting that previously disclosed flaws remain exploitable and unpatched in current versions.
← Back to all stories