- Anthropic’s Claude extension flaws permit pretend clicks to launch delicate AI workflows
- Researchers discovered susceptible handlers unchanged throughout eight extension updates
- Artificial clicks bypassed checks designed to substantiate actual consumer actions
Safety researchers at Manifold Safety have claimed Anthropic’s Claude for Chrome browser extension accommodates two unpatched vulnerabilities in model 1.0.80, launched July 7, 2026.
In keeping with Manifold Safety, it first reported each vulnerabilities to Anthropic by means of the corporate’s bug bounty program on Could 21, 2026, and obtained acknowledgment the next day.
The primary flaw lets any browser extension set off 9 predefined Claude workflows by simulating an artificial consumer click on on claude.ai.
9 workflows and one lacking examine
Researcher Ax Sharma discovered that the extension by no means verified whether or not a click on occasion carried the Occasion.isTrusted property earlier than appearing on it.
Underneath default settings, the vulnerability obtained a CVSS rating of seven.7 Excessive, rising to 9.6 Important when customers enabled computerized execution as a result of Claude might carry out actions with out approval.
The 9 hardcoded duties embody studying Gmail, opening Google Docs, checking Google Calendar, and modifying Salesforce leads with out asking.
As a result of the browser marks artificial clicks as untrusted, the extension ought to have rejected them however as an alternative executed the workflow anyway.
Manifold Safety confirmed on July 7 2026 that each vulnerabilities nonetheless work towards model 1.0.80, months after first reporting them to Anthropic.
Anthropic launched eight separate variations between 1.0.73 and 1.0.80 with out altering the particular handlers’ researchers had already flagged as susceptible.
The corporate closed the synthetic-click report, saying an present inside report already tracked the broader trust-boundary challenge researchers had described intimately.
Nonetheless, Sharma believes the repair required just one extra line of code to confirm the clicking occasion’s isTrusted property earlier than permitting the workflow to proceed.
A second, structural weak point
A second flaw includes a side-panel URL parameter known as skipPermissions, which may activate a privileged mode with none consent immediate.
When the parameter is ready to true, the panel begins skipping permission checks totally, permitting Claude to behave with out asking the consumer first.
Manifold notes that solely Anthropic’s personal scheduled-task characteristic is meant to assemble this type of privileged URL internally proper now.
The panel, nevertheless, honours that parameter no matter which script or web page really constructed the originating URL string in follow.
One instance job lets Claude learn a consumer’s Gmail inbox, establish promotional messages, and robotically click on the unsubscribe hyperlinks inside them.
Manifold warns that “the bypass continues to be six strains of JavaScript,” months after researchers first flagged the underlying challenge to Anthropic.
Anthropic categorised this second discovering as informational, arguing that the parameter is just ever constructed by its personal inside methods.
Manifold mentioned the content-script and side-panel code linked to each vulnerabilities remained byte-identical throughout the eight subsequent extension releases examined after the unique report.
The failings had been additionally reproduced throughout Claude’s Opus, Sonnet, and Fable side-panel mannequin alternatives, indicating that the difficulty affected the extension’s safety design reasonably than the underlying synthetic intelligence fashions.
The report additionally linked the findings with OWASP considerations involving LLM01: Immediate Injection and LLM06: Extreme Company dangers in AI functions.
The researchers famous that abuse involving AI instruments might stay tough to detect as a result of regular browser exercise and community connections can seem unchanged whereas unauthorized AI actions happen.
Comply with TechRadar on Google Information and add us as a most well-liked supply to get our professional information, opinions, and opinion in your feeds.

