1Password injects login credentials directly into websites without granting Claude access to passwords — but afterward the AI operates unrestricted within the user account.
The version limits web searches (default 200 per session) and subagent spawns (default 200 per session) to prevent runaway loops, automatically moves MCP tools running longer than 2 minutes to the background, and fixes several critical bugs in execution logic and Windows compatibility.
Anthropic has executed large-scale code migrations of millions of lines in weeks where previously years and millions of dollars were required — made possible through Claude-based agentic workflows and focused process management.
Claude Fable 5 is reserved in Claude Cowork for multi-step, complex workflows where sustained context continuity and self-correction capabilities are essential.
A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.
Anthropic apparently disregarded the European Parliament’s expectations by sending a technician instead of authorized management, exposing enforcement weaknesses in AI company regulation.
Loop Engineering automates the control of AI agents through loops rather than manual prompt engineering and is seen by developers at Anthropic, OpenAI and Google as a new standard.
The update addresses security vulnerabilities in permission previews, errors in subagent model resolution, and critical bugs in parallelization and persistence.
Nested links on a malicious website enabled Claude to exfiltrate sensitive user data such as name, location, and employer via URLs, despite Anthropic having implemented protective measures.
Manipulated browser extensions can trick the Claude extension into performing actions in Gmail, Google Docs, and Calendar contexts, which Manifold Security has reproduced since May and Anthropic has yet to fix.
Two unpatched vulnerabilities in Claude for Chrome allow data exfiltration from Google services because the activation mechanism does not verify whether user interactions are genuine.