Skip to content
Agentic AI Security Hub
Back to feed
Severity: HighVulnerabilityMCP/tool abuse

Malicious browser extension can simulate user input to Claude AI extension, gaining unauthorized access to connected services

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

A vulnerability in Anthropic's Claude Chrome extension allows a malicious extension to trigger predefined AI actions by simulating user clicks. An attacker could exploit this flaw to abuse Claude's permissions to connected services including Gmail, Google Docs, Google Calendar, and Salesforce.

What to do

Restrict Claude extension permissions and isolate agentic AI instances from direct service integrations using a centralized gateway.

#Claude#browser extension#privilege escalation#third-party integrations#input simulation