Sicurezza AI · Attacco ad app web
L'estensione Chrome di Anthropic Claude permetteva a siti web di iniettare prompt nell'assistente senza clic dell'utente.
1 fonte · 26 mar
The Hacker News
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Claude extension flaw enabled silent prompt injection via XSS and weak allowlist, risking data theft and impersonation until Feb 19, 2026 fix.
originalePart of the PlainSec briefing for 2026-03-26
Every edition of this story: Estensione Claude per Chrome permetteva prompt silenti da siti web