A security vulnerability in the Claude Chrome Extension allows malicious extensions to trigger AI actions and access connected services such as Gmail and Google Docs.
Manipulated browser extensions can trick the Claude extension into performing actions in Gmail, Google Docs, and Calendar contexts, which Manifold Security has reproduced since May and Anthropic has yet to fix.
Malicious browser extensions can leverage Claude Tasks in Chrome to access Gmail, Docs, and Calendar, but already require script execution rights on claude.ai.