'The bypass is still six lines of JavaScript': Security experts warn that Claude for Chrome browser extension…

https://cdn.mos.cms.futurecdn.net/hkechUkk5KHAbcMTCNVxG4-1920-80.png
  • Anthropic’s Claude extension flaws allow fake clicks to launch sensitive AI workflows
  • Researchers found vulnerable handlers unchanged across eight extension updates
  • Synthetic clicks bypassed checks designed to confirm real user actions

Security researchers at Manifold Security have claimed Anthropic's Claude for Chrome browser extension contains two unpatched vulnerabilities in version 1.0.80, released July 7, 2026.

According to Manifold Security, it first reported both vulnerabilities to Anthropic through the company's bug bounty program on May 21, 2026, and received acknowledgment the following day.

The first flaw lets any browser extension trigger nine predefined Claude workflows by simulating a synthetic user click on claude.ai.

Nine workflows and one missing check

Researcher Ax Sharma found that the extension never verified whether a click event carried the Event.isTrusted property before acting on it.

Under default settings, the vulnerability received a CVSS score of 7.7 High, increasing to 9.6 Critical when users enabled automatic...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE