Claude Chrome Extension Vulnerability Could Let Malicious Extensions Access Gmail and Connected Services

A security flaw in Anthropic’s Claude for Chrome browser extension could allow a malicious browser extension to trigger predefined AI actions by simulating user clicks, potentially giving attackers access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. The vulnerability was disclosed by security researchers who demonstrated the attack vector.

The flaw works by exploiting the extension’s permissions model, which grants Claude access to various Google services when the user has authorised those connections. A separate malicious extension running in the same browser can programmatically interact with the Claude interface, causing it to perform actions on the user’s behalf without their knowledge or consent.

Anthropic had previously restricted the arbitrary-prompt attack path in May as part of its response to an earlier disclosure. However, researchers found that the underlying architectural issue remained exploitable through a different mechanism, bypassing the earlier fix.

The vulnerability affects users who have installed the Claude for Chrome extension and granted it access to their Google services. Malicious extensions would need to be installed separately – through social engineering, compromised developer accounts, or other distribution methods – but once present, they could leverage the Claude extension’s authorised access without triggering additional security warnings.

Anthropic has been notified of the vulnerability and is expected to release an update addressing the issue. Users are advised to review which extensions have permission to interact with the Claude extension and to remove any extensions from untrusted sources.