// Alert

Gmail threat report

Security researchers demonstrated an indirect prompt-injection vulnerability in Claude's Chrome browser extension that enables attackers to intercept Gmail verification codes and authentication secrets. An attacker can craft malicious email content that, when summarized by the Claude agent, executes arbitrary JavaScript within the victim's authenticated Gmail session to query the Atom feed, extract verification codes, and hijack accounts on Slack, X, and Claude.ai. The attack exploits Claude's access to untrusted email content combined with powerful browser permissions.

// Get alerts for Gmail