Researchers at Manifold Security have disclosed two vulnerabilities in the Claude for Chrome browser extension that could allow rogue extensions to trigger Gmail reads and other sensitive actions. The first flaw, tracked as a high-severity issue (CVSS 7.7 in default mode, 9.6 critical with ‘Act without asking’ enabled), involves a content script that listens for clicks on a specific element on claude.ai. The script fails to check the event.isTrusted property, allowing any other extension with access to the claude.ai DOM to dispatch a synthetic click and trigger one of nine allowlisted tasks, including reading Gmail, Google Docs, and Calendar data. The second issue involves a ?skipPermissions=true URL parameter that bypasses all permission checks when the side panel loads, though it is currently only exploitable by the extension itself. Manifold reported both issues on May 21, 2026, against version 1.0.72. Anthropic acknowledged the reports but closed them, stating the first was already tracked under the earlier ClaudeBleed flaw and the second was considered informative. However, as of July 14, 2026, version 1.0.80 still contains the vulnerable code. The Hacker News confirmed the flaws remain unpatched. Users are advised to disable ‘Act without asking’ mode and review extensions with permissions on claude.ai.
Companies: Manifold Security, Anthropic, The Hacker News, LayerX
Products: Claude for Chrome, Claude Code, Google Chrome, Gmail, Google Docs, Calendar
Original source: thehackernews.com