Severity: HighVulnerabilityMCP/tool abuse
Malicious browser extension can simulate user input to Claude AI extension, gaining unauthorized access to connected services
Global
Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.
A vulnerability in Anthropic's Claude Chrome extension allows a malicious extension to trigger predefined AI actions by simulating user clicks. An attacker could exploit this flaw to abuse Claude's permissions to connected services including Gmail, Google Docs, Google Calendar, and Salesforce.
What to do
Restrict Claude extension permissions and isolate agentic AI instances from direct service integrations using a centralized gateway.
Mapped framework pillars
Sources
#Claude#browser extension#privilege escalation#third-party integrations#input simulation
