// SlackHIGH
Security researchers at Zenity Labs demonstrated an indirect prompt-injection attack chain in Claude in Chrome that enables account takeovers of Slack and other services. The exploit tricks the AI agent into executing arbitrary code within authenticated browser sessions, allowing attackers to intercept email-based verification codes used for Slack account authentication. The vulnerability chain involves malicious email content, package registry manipulation, and automated credential theft.
// Get alerts for Slack