Briefing

Browser Extension Vulnerability Lets Rogue Scripts Trigger Claude for Chrome Tasks

security
by [email protected] (The Hacker News) · Claude Anthropic

Disable or remove any rogue browser extensions that can run scripts on claude.ai and update the Claude for Chrome extension to the latest patched version.

What to do now

Uninstall any non‑official browser extensions that can run scripts on claude.ai, update Claude for Chrome to the latest patched version, and audit your browser for malicious scripts.

Summary

Any browser extension that can run a script on claude.ai can trigger Claude for Chrome tasks aimed at Gmail, Google Docs, and Calendar. Both this and ClaudeBleed require a rogue extension that can run scripts on claude.ai; the difference is in scope. Anthropic restricted the arbitrary‑prompt path in May as part of its response to a prior vulnerability. The vulnerability allows malicious scripts to execute privileged Claude for Chrome actions, potentially manipulating user data in Gmail, Docs comments, and Calendar events. The issue is tied to the extension’s capability to inject code into claude.ai pages. The fix involves updating the Claude for Chrome extension to the patched version. Users should remove any non‑official extensions that can run scripts on claude.ai and audit their browsers for malicious scripts.

Key changes

  • Rogue browser extensions that can run scripts on claude.ai can trigger Claude for Chrome tasks targeting Gmail, Google Docs, and Calendar
  • Both the rogue extension and ClaudeBleed require the ability to run scripts on claude.ai; scope differs
  • Anthropic restricted the arbitrary‑prompt path in May as part of its response to a prior vulnerability
  • The vulnerability allows malicious scripts to execute privileged Claude for Chrome actions
  • The attack can manipulate user data in Gmail, Docs comments, and Calendar events
  • The issue is tied to the extension’s capability to inject code into claude.ai pages
  • The fix involves updating the Claude for Chrome extension to the patched version
  • Users should remove any non‑official extensions that can run scripts on claude.ai and audit their browsers for malicious scripts

Affects

none

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting