Skip to content

Claude for Chrome: Malicious Extensions Can Trigger Gmail Access

The Point: Malicious browser extensions can leverage Claude Tasks in Chrome to access Gmail, Google Docs, and Google Calendar, but already require script execution rights on claude.ai.

A vulnerability in Claude for Chrome allows malicious browser extensions to access a user’s Gmail, Google Docs, and Google Calendar, as long as the extension already has the ability to execute scripts on claude.ai.

The vulnerability affects Claude for Chrome and allows malicious browser extensions to trigger automated tasks against Gmail, Google Docs including their comments, and Google Calendar. The prerequisite is that the extension already has the ability to execute scripts on claude.ai.

This gap is directly related to a previous vulnerability called ClaudeBleed. Both attack vectors require that a malicious extension can generally execute code on the Claude website – the difference lies in the scope of possible actions. Anthropic had already taken action in May of this year and restricted the so-called arbitrary-prompt path in response to previous security issues.

For CISOs, this means that the isolation of browser extensions remains critical in the context of AI integration. It is necessary to monitor and control the access of extensions to sensitive web applications such as claude.ai, especially when these are deployed at the enterprise level.


Source: thehackernews.com · Published July 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: