Skip to content
Agentic AI Security Hub
Back to feed
Severity: HighVulnerabilityMCP/tool abuse

Claude for Chrome vulnerability exposes Gmail and Google Workspace access via malicious extensions

Global

Live intelligence. Items are aggregated from public sources and summarised automatically. Always verify against the linked source before acting.

A flaw in Claude for Chrome allows malicious browser extensions running on claude.ai to trigger agent tasks that access Gmail, Google Docs, and Calendar without explicit user consent. The vulnerability requires a rogue extension already capable of executing scripts on the claude.ai domain, but demonstrates how compromised extensions can hijack AI agent capabilities to access sensitive user data.

What to do

Enforce zero-trust verification of all agent-initiated integrations and restrict extensions' permissions to access AI platform APIs.

#Claude#browser extension#credential abuse#agent hijacking#Gmail access#Google Workspace