Anthropic's Claude for Chrome extension flaw lets malicious add‑ons read Gmail and Google Docs
Security firm Manifold reported that two vulnerabilities in Anthropic's Claude for Chrome browser extension remain exploitable despite recent patches. The flaws allow a malicious extension to trigger Claude actions without a genuine user click, enabling it to read Gmail messages, Google Docs, and calendar entries. The attack works by injecting a DOM element that mimics a click on the #claude-onboarding-button, bypassing the confirmation prompt, especially when the user has enabled Claude's autonomous “Act without asking” mode. Exploitation requires a second, malicious extension with script access, meaning the risk is not trivial but can compromise sensitive data if present. Manifold’s findings echo earlier “ClaudeBleed” issues and highlight that the extension’s default safeguards can be overridden. Users are advised to limit installed extensions, review permissions regularly, keep software updated, and consider disabling autonomous mode to mitigate the threat.