As per reports, a vulnerability has been identified within the Claude browser extension for Google Chrome that allows malicious extensions to trigger predefined artificial intelligence tasks by simulating synthetic user actions.
Following are the details:
• The security weakness was discovered by researchers from Manifold Security, who confirmed that the flaw affects the browser extension version released on Tuesday (07 July).
• The vulnerability allows a separate, malicious browser extension with permissions to run on the claude.ai domain to inject elements into the webpage and generate synthetic click events.
• The browser extension fails to verify whether a click event originates from an actual user by checking the browser trusted event property before executing its predefined workflows.
• Although the browser automatically marks JavaScript-generated events as untrusted, the Claude extension processes them as legitimate, allowing unauthorized execution of built-in tasks.
• The vulnerable workflows can trigger activities such as scanning and unsubscribing from emails, accessing Google Documents comments, generating calendar invites, or modifying customer relationship leads in Salesforce.
• The issues were disclosed to Anthropic through their security report program.
