{"id":1065,"date":"2026-07-18T09:10:48","date_gmt":"2026-07-18T07:10:48","guid":{"rendered":"https:\/\/familiebuckens.nl\/?p=1065"},"modified":"2026-07-20T09:11:16","modified_gmt":"2026-07-20T07:11:16","slug":"claude-for-chrome-flaw-allows-malicious-extensions-to-abuse-ai-privileges","status":"publish","type":"post","link":"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/18\/claude-for-chrome-flaw-allows-malicious-extensions-to-abuse-ai-privileges\/","title":{"rendered":"Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">A security weakness in Anthropic\u2019s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The issue was discovered by Manifold Security researcher Ax Sharma, who found that Claude for Chrome did not adequately distinguish between a genuine user interaction and a synthetic click generated through JavaScript.<\/p>\n\n\n<a class=\"wp-block-read-more\" href=\"https:\/\/familiebuckens.nl\/index.php\/2026\/07\/18\/claude-for-chrome-flaw-allows-malicious-extensions-to-abuse-ai-privileges\/\" target=\"_self\"><a href=\"https:\/\/www.linkedin.com\/pulse\/warning-claude-chrome-flaw-allows-malicious-extensions-4wnge\/\">(1) WARNING: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges | LinkedIn<\/a><span class=\"screen-reader-text\">: Claude For Chrome Flaw Allows Malicious Extensions To Abuse AI Privileges<\/span><\/a>","protected":false},"excerpt":{"rendered":"<p>A security weakness in Anthropic\u2019s Claude for Chrome extension could allow another malicious browser extension to activate predefined AI workflows without a genuine user click, potentially exposing information held in Gmail, Google Docs and Google Calendar or initiating actions in services such as Salesforce. The issue was discovered by Manifold&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[17],"tags":[72],"class_list":["post-1065","post","type-post","status-publish","format-standard","hentry","category-vulnerability","tag-72"],"_links":{"self":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1065","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/comments?post=1065"}],"version-history":[{"count":1,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1065\/revisions"}],"predecessor-version":[{"id":1066,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/posts\/1065\/revisions\/1066"}],"wp:attachment":[{"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/media?parent=1065"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/categories?post=1065"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/familiebuckens.nl\/index.php\/wp-json\/wp\/v2\/tags?post=1065"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}