Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    SpaceX IPO in Hours. Going to the Moon, $200+

    June 12, 2026

    vivo X Fold6 confirmed to feature a special edition Dimensity 9500 SoC

    June 12, 2026

    Your 4K Blu-ray disc has HDR — but not all HDR is the same

    June 12, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover
    Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover
    Cybersecurity

    Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover

    The Tech GuyBy The Tech GuyMay 9, 2026No Comments3 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    A vulnerability in the Claude extension for Chrome could allow attackers to take over the AI agent and abuse it for information theft, cybersecurity firm LayerX reports.

    Advertisement

    The flaw, dubbed ClaudeBleed, is a combination of lax permissions, where any Chrome extension can run commands in Claude in Chrome, and poorly implemented trust in the origin of the command, not the execution context.

    According to LayerX, the main issue is that the Claude extension allows interaction with any script running in the origin browser, without verifying its owner.

    “As a result, any extension can invoke a content script (which does not require any special permissions) and issue commands to the Claude extension,” the company explains.

    Claude in Chrome, it says, trusts the origin of the execution, which is claude.ai, and not the execution context, thus allowing any JavaScript running in the origin to issue privileged commands.

    This allows an attacker to create an extension with a declared content script and configured to run in the Main world, thus ensuring the script is executed as part of the page, and send a message to the Claude extension, which trusts the sender because it runs in claude.ai.

    Advertisement. Scroll to continue reading.

    Because a message handler in Claude in Chrome accepts and forwards arbitrary prompts, the attacker can perform remote prompt injection and control the AI agent’s actions.

    While Claude enforces user confirmation for sensitive actions, as well as policies that prevent certain actions, and makes decisions based on certain inputs, LayerX discovered that the attacker’s script could bypass these protections.

    The company was able to forge user approval by repeatedly sending a confirmation message and relied on Document Object Model (DOM) manipulation to dynamically modify UI elements and alter Claude’s perception of the actions.

    It was also able to gain visibility into command execution through repeated triggering of the action and by observing the effects.

    “This vulnerability effectively breaks Chrome’s extension security model by allowing a zero-permission extension to inherit the capabilities of a trusted AI assistant,” LayerX says.

    This attack chain, the company says, allows an attacker to weaponize Claude to exfiltrate data from Gmail, GitHub, or Google Drive, as well as to send emails, delete data, and share documents on behalf of the user.

    When notified of the issue, Anthropic told LayerX it was working on a patch, but the fix only partially addressed the underlying vulnerability, through “internal security checks to prevent extensions running in ‘standard’ mode from executing remote commands”.

    Because the root cause of the weakness was not addressed, an attacker can simply switch the extension to ‘privileged’ mode and bypass the fix. The user is never notified or asked to approve the switch, LayerX says.

    Related: Claude Code OAuth Tokens Can Be Stolen Through Stealthy MCP Hijacking

    Related: Claude AI Guided Hackers Toward OT Assets During Water Utility Intrusion

    Related: Anthropic Unveils Claude Security to Counter AI-Powered Exploit Surge

    Related: Claude Code, Gemini CLI, GitHub Copilot Agents Vulnerable to Prompt Injection via Comments

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    CISA Directs Federal Agencies to Prioritize Security Patches Based on Risk

    June 12, 2026

    Alert Fatigue Is Becoming a Security Threat of Its Own

    June 11, 2026

    Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks

    June 11, 2026

    ‘GreatXML’ Zero-Day Exploit Bypasses BitLocker

    June 11, 2026

    Aryon Security Raises $29 Million in Series A Funding

    June 11, 2026

    Cyera Raises $600 Million at $12 Billion Valuation

    June 10, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 202625 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views

    ChatGPT Group Chats are here … but not for everyone (yet)

    November 14, 20259 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    SpaceX IPO in Hours. Going to the Moon, $200+

    June 12, 2026

    vivo X Fold6 confirmed to feature a special edition Dimensity 9500 SoC

    June 12, 2026

    Your 4K Blu-ray disc has HDR — but not all HDR is the same

    June 12, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.