// ClaudeHIGH
AI security firm Manifold disclosed two unpatched vulnerabilities in Claude for Chrome that persist despite eight security patches since May. The flaws allow malicious browser extensions to bypass approval mechanisms and trigger Claude to perform actions on behalf of users without genuine consent, enabling unauthorized access to Gmail messages, Google Docs documents, and calendar entries.
- Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Cal(opens in a new tab)
- Claude for Chrome Vulnerability Lets Attackers Read Gmail, Docs,(opens in a new tab)
- Claude Chrome Flaw Exposes User Data - Time News(opens in a new tab)
- Claude in Chrome Flaw: ‘Act Without Asking’ Mode Can Be Exploite(opens in a new tab)
- Claude’s Chrome extension still has hidden security gaps, as res(opens in a new tab)
- Claude’s Chrome extension still has hidden security gaps, as res(opens in a new tab)
// Get alerts for Claude