Anthropic is merging the Chrome extension with Claude Cowork, allowing browser sessions to continue seamlessly across desktop, web and mobile apps, initially available for Max…
The popular HTTP header extension ModHeader contained code to capture browser history that could have been activated through a simple update without additional permissions.
A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.
Manipulated browser extensions can trick the Claude extension into performing actions in Gmail, Google Docs, and Calendar contexts, which Manifold Security has reproduced since May…
Malicious browser extensions can leverage Claude Tasks in Chrome to access Gmail, Docs, and Calendar, but already require script execution rights on claude.ai.
Google and Microsoft pulled the 1.6-million-times-installed header-editing extension ModHeader after researchers discovered a dormant browsing-history-collector component.
A fake Perplexity extension on the Chrome Web Store was discovered intercepting search queries and browsing data, transmitting them to attackers’ servers.
Attacks on popular AI brands exploit rapid employee trust in new productivity tools and create a governance blind spot in browser extension management.