ClaudeBleed Vulnerability Lets Hackers Hijack Claude Chrome Extension to Steal Data

https://hackread.com/wp-content/uploads/2026/05/claudebleed-vulnerability-hackers-claude-chrome-extension-1024x554.jpg

Cybersecurity researchers from LayerX have found a major security flaw in the Claude for Chrome browser extension that could allow hackers to take full control of the AI assistant. They have named this vulnerability ClaudeBleed, and their research shows that even a basic extension with no special permissions can hijack Claude to steal private files and send emails without the user’s knowledge or consent.

The Root Cause of the ClaudeBleed Vulnerability

The problem started with a mistake in how the extension identifies the source of incoming messages, leading to a critical trust boundary violation. As noted by LayerX’s senior researcher Aviad Gispan, the Claude Chrome extension was set up with a setting called externally_connectable, which allowed any script running on the claude.ai website to send commands to the extension.

Since the extension trusts the website and doesn’t check who is actually running the script, hackers could use a content script...

Copyright of this story solely belongs to hackread.com. To see the full text click HERE

Read more

https://substackcdn.com/image/fetch/$s_!sGDs!,w_1200,h_675,c_fill,f_jpg,q_auto:good,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F250e5...

An analysis based on current valuations of OpenAI and Anthropic suggests ~$370B of philanthropic assets tied to the two AI companies are poised to become liquid

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data