Claude’s Chrome extension still has hidden security gaps, as researchers warn simple tricks can trigger powerful AI actions



  • Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows
  • Researchers found vulnerable handlers unchanged across eight extension updates
  • Synthetic clicks bypassed checks designed to confirm real user actions

Security researchers at Manifold Security have claimed Anthropic’s Claude for Chrome browser extension contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.

According to Manifold Security, it first reported both vulnerabilities to Anthropic through the company’s bug bounty program on May 21, 2026, and received acknowledgment the following day.

https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1920-80.png



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img