Skip to content

Unpatched Vulnerabilities in Claude Chrome Extension Enable Data Exfiltration

In a nutshell: Two unpatched vulnerabilities in Claude for Chrome allow data exfiltration from Google services because the activation mechanism does not verify whether user interactions are genuine.

Security firm Manifold has documented two vulnerabilities in Anthropic’s Claude extension for Chrome (version 1.0.80) that allow malicious browser extensions to access Gmail, Google Docs, and calendar entries without genuine user consent.

Manifold describes two structural security gaps: The first concerns the activation mechanism for predefined tasks, which does not validate whether a click originates from a genuine user. In standard mode, confirmation would be required; in autonomous mode, however, the extension performs actions without prior user inquiry — and thus also allows malicious browser extensions to retrieve data without the user’s knowledge. The second vulnerability lies in the sidebar’s URL parameters, which allow the click-free mode to be loaded directly.

The core problem arose from an incomplete security update that Anthropic released following the original ClaudeBleed vulnerability. This update was intended to restrict access to predefined tasks but failed to verify the authenticity of user interactions. At the time, Anthropic characterized this list as a temporary interim solution.

Manifold reported the vulnerabilities to Anthropic on May 21, 2026. According to the security researchers, the vulnerability has not been closed in any of the eight browser extension versions released since then. An official statement from Anthropic is not yet available. For CISOs, this is relevant: These vulnerabilities endanger all users of the Claude extension in autonomous mode if they have also installed malicious browser extensions. A complete fix is still pending.


Source: www.it-daily.net · Published July 15, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.7.3.

Share on: