< Back to all clusters
[TECHNOLOGY] · Italy, France · 3 sources

Anthropic Claude Chrome extension flaw lets attackers read Gmail, Docs and Calendar

Security researchers at Manifold Security disclosed two unresolved vulnerabilities in Anthropic's Claude for Chrome extension. The first flaw lets any browser extension simulate a user click on Claude’s interface, bypassing the standard trust check and triggering one of nine pre‑approved tasks, including reading the user’s Gmail, opening the latest Google Doc with comments, and accessing the Google Calendar. When the optional "act without prompting" mode is enabled, the exploit can run silently, raising its CVSS score to 9.6 (critical).

The second vulnerability is a dormant privilege‑escalation path: loading the extension’s side‑panel with the URL parameter "?skipPermissions=true" disables the user‑approval step entirely. Although currently only the Claude extension can generate this URL, researchers warn that future exploits could combine the two flaws for full account takeover. Anthropic acknowledged the reports on 21 May 2026 and marked the issues as resolved, but the bugs remain exploitable in version 1.0.80 released 7 July 2026.