07/23/2026
Researchers disclosed a vulnerability in the Claude in Chrome browser extension that allowed malicious extensions with no declared permissions to silently access Gmail, Google Drive, and GitHub data. Anthropic released a patch, but researchers note it remains exploitable in certain configurations.
When AI tools operate at the browser level with access to authenticated sessions, knowing what they can reach and under what conditions isn't optional, it's part of your security posture.
https://cybersecuritynews.com/claudes-chrome-extension-vulnerability/
A critical flaw in the “Claude in Chrome” extension lets attackers hijack the AI assistant to silently steal Gmail, Drive, and GitHub data.