ainewsblitz.com

Breaking

Unpatched Claude for Chrome Flaw Lets Malicious Extensions Trigger AI Actions on Gmail, Salesforce

  • Security
  • AI Agents

A vulnerability in Anthropic's "Claude for Chrome" browser extension allows malicious extensions to trigger the AI assistant's pre-defined workflows without genuine user interaction, potentially exposing connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. The issue, discovered by Ax Sharma of Manifold Security, remains unpatched in the latest release despite being reported months earlier, according to reporting on the finding BleepingComputer.

Continue reading

The rest of this article is for AI News Blitz readers. Choose an option below to keep reading.

$20
Read this article
$29/month
Unlimited — all 7,548 articles, the full archive, and comprehension quizzes
Save 72%
$98/year
≈ $8.17/month
Unlimited, billed once a year