BREAKING
Two Unpatched Flaws in Claude for Chrome
0
unpatched flaws
0
lines of JS
0
releases, no fix
How the click bypass works
1Malicious ext dispatches click
2Handler skips isTrusted check
3Predefined task runs
4Gmail, Docs, Calendar read
CVSS: 7.7 High to 9.6 Critical
Default7.7
Act w/o asking9.6
Reporting vs remediation gap
ReportedMay 21, 2026
Two flaws sent to Anthropic
v1.0.73 to v1.0.80 shipped
DisclosedJuly 14, 2026
Still unpatched at v1.0.80
Model-independent design flaw
Disable Act without asking; scope permissions
AI NEWS BLITZ
Researchers reveal two unpatched flaws in Anthropic's Claude for Chrome extension.