BotBeat
...
← Back

> ▌

AnthropicAnthropic
RESEARCHAnthropic2026-05-09

ClaudeBleed: Critical Vulnerability Allows Any Chrome Extension to Hijack Anthropic's Claude AI

Key Takeaways

  • ▸ClaudeBleed allows any Chrome extension to inject commands into Claude's messaging interface, bypassing permission checks entirely
  • ▸Attackers can exfiltrate sensitive user data (emails, GitHub repos, Google Drive files) and manipulate Claude into performing unauthorized actions
  • ▸Anthropic's patch in v1.0.70 provides only partial mitigation; core vulnerabilities remain under "Act without asking" mode and alternative execution flows
Source:
Hacker Newshttps://cyberinsider.com/claudebleed-allows-any-chrome-extension-to-control-anthropics-ai-assistant/↗

Summary

A critical security vulnerability dubbed "ClaudeBleed" has been discovered in Anthropic's "Claude in Chrome" browser extension, allowing any Chrome extension—even those with zero permissions—to hijack Claude's capabilities and perform sensitive actions without meaningful user consent. Researchers at LayerX identified that the flaw stems from a trust boundary failure in how the extension handles communication between scripts on claude.ai and the extension itself, exploiting Chrome's externally_connectable feature. The vulnerability could enable attackers to steal emails, access private GitHub repositories, exfiltrate Google Drive files, and manipulate Claude into executing browser actions on behalf of users.

The core issue lies in the extension's failure to verify whether scripts are actually from Anthropic or have been injected by malicious extensions. Proof-of-concept attacks successfully extracted sensitive data from Google Drive, sent emails through Gmail, and accessed private GitHub repositories. Researchers also discovered weaknesses in Claude's approval system, including an "approval looping" technique that allows bypassing safeguards by repeatedly submitting automated requests. Additionally, DOM manipulation attacks could trick Claude into treating dangerous actions as harmless ones.

Anthropicresponded quickly after LayerX's April 27 report, but the partial fix in extension version 1.0.70 only mitigates the issue, leaving the core trust model vulnerable. Attackers can still bypass protections by abusing Claude's "Act without asking" mode or triggering alternative execution flows. Researchers recommend restricting extension communications to trusted IDs, implementing authenticated message signing, and tying user approvals to one-time actions that cannot be replayed. Users are advised to review installed extensions carefully and disable autonomous AI browsing modes.

  • The vulnerability reveals fundamental security gaps in integrating powerful AI assistants into browsers without proper isolation and trust verification

Editorial Opinion

ClaudeBleed exposes a critical mismatch between Chrome's extension permission model and the capabilities of modern AI assistants. While Anthropic's rapid response is commendable, the partial nature of the fix suggests deeper architectural weaknesses in how AI systems verify trust boundaries and user intent. This incident should serve as a sobering reminder that as language models gain autonomous access to user data and actions, security assumptions built for less powerful tools are dangerously inadequate. The industry must rethink how AI assistants integrate with browsers and operating systems before trust boundaries become meaningless.

Generative AICybersecurityAI Safety & AlignmentPrivacy & Data

More from Anthropic

AnthropicAnthropic
OPEN SOURCE

Anthropic Releases Prempti: Open-Source Guardrails for AI Coding Agents

2026-05-12
AnthropicAnthropic
PRODUCT LAUNCH

Anthropic Unleashes Computer Use: Claude 3.5 Sonnet Now Controls Your Desktop

2026-05-12
AnthropicAnthropic
PARTNERSHIP

SpaceX Backs Anthropic with Massive Data Centre Deal Amidst Musk's OpenAI Legal Battle

2026-05-12

Comments

Suggested

AnthropicAnthropic
OPEN SOURCE

Anthropic Releases Prempti: Open-Source Guardrails for AI Coding Agents

2026-05-12
AnthropicAnthropic
PRODUCT LAUNCH

Anthropic Unleashes Computer Use: Claude 3.5 Sonnet Now Controls Your Desktop

2026-05-12
MetaMeta
POLICY & REGULATION

Meta Employees Protest Mouse Tracking Technology at US Offices

2026-05-12
← Back to news
© 2026 BotBeat
AboutPrivacy PolicyTerms of ServiceContact Us