Vulnerabilities · 60 days ago
Claude for Chrome still treats a forged click like a real one, so another extension can drive the assistant into connected Gmail, Docs, and Calendar data. The broken assumption is interaction, not prompts: whitelisting tasks does not help if the activation gesture itself can be spoofed.
Manifold says the flaw remains exploitable across eight released updates, including 1.0.80, despite Anthropic’s earlier ClaudeBleed mitigation. In default mode the chain hits a confirmation prompt before sensitive actions, but in "Act without asking" the same trust gap can let the action proceed with no visible warning.
The second design gap is a direct launch path into that no-confirmation mode from the side panel’s own URL logic. That makes the extension a browser-level trust boundary problem for any environment where an AI assistant can reach mail, documents, or calendars.
3 sources covering this story
Claude Chrome extension flaw lets malicious extensions trigger AI actions
A flaw in Anthropic's Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claude's access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
Claude for Chrome v1.0.80 still accepts forged clicks from other extensions, triggering Gmail, Docs, and Calendar tasks silently in hands-off mode.
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
A ClaudeBleed-linked vulnerability reportedly persists across eight patches, exposing potentially sensitive data to other extensions.
Part of the PlainSec briefing for 2026-07-14