Security · 20h ago
Claude Chrome extension still vulnerable despite Anthropic fixes
Security researchers warn that Anthropic's Claude for Chrome extension remains vulnerable to hijacking via fake clicks and permission bypasses, requiring only six lines of JavaScript to exploit. The flaw persists despite multiple updates from Anthropic, which the researchers reported repeatedly. The extension's design allows attackers to trick users into granting unintended permissions.
Meridian48 take
Anthropic's slow response to a simple, repeatedly reported exploit raises questions about its security review processes for AI tools.
Read the full reporting
'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension could be hijacked, despite it alerting Anthropic several times that something was wrong →
TechRadar
claude-extensionchrome-vulnerability