Claude for Chrome Still Trusts Fake Clicks

Claude for Chrome still treats a forged click like a real one, so another extension can drive the assistant into connected Gmail, Docs, and Calendar data. The broken assumption is interaction, not prompts: whitelisting tasks does not help if the activation gesture itself can be spoofed. Manifold says the flaw remains exploitable across eight released updates, including 1.0.80, despite Anthropic’s earlier ClaudeBleed mitigation. In default mode the chain hits a confirmation prompt before sensitive actions, but in "Act without asking" the same trust gap can let the action proceed with no visible warning. The second design gap is a direct launch path into that no-confirmation mode from the side panel’s own URL logic. That makes the extension a browser-level trust boundary problem for any environment where an AI assistant can reach mail, documents, or calendars.

Part of the PlainSec briefing for 2026-07-14

Sources