Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
A security flaw in the "Claude for Chrome" extension has been identified, allowing malicious browser extensions to access and potentially read your Gmail messages, Google Docs, and Calendar events. This vulnerability stems from the ability of any script-running extension on claude.ai to trigger tasks within the Chrome extension. While similar to another issue called "claudeBleed," this flaw has a broader scope of potential impact. The discovery underscores the importance of securing browser extensions and highlights the risks associated with granting extensions broad access to personal data across various Google services.
Original Source
Read the full article at Thehackernews →KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.