// GmailHIGH
Security researchers demonstrated an indirect prompt-injection vulnerability in Claude's Chrome browser extension that enables attackers to intercept Gmail verification codes and authentication secrets. An attacker can craft malicious email content that, when summarized by the Claude agent, executes arbitrary JavaScript within the victim's authenticated Gmail session to query the Atom feed, extract verification codes, and hijack accounts on Slack, X, and Claude.ai. The attack exploits Claude's access to untrusted email content combined with powerful browser permissions.
- Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Ta(opens in a new tab)
- Cybersecurity Newsletter Weekly – Top 50 Biggest Cybersecurity S(opens in a new tab)
// Get alerts for Gmail