‘No clicks, no permission prompts. Just visit a page, and an attacker completely controls your browser’: Experts warn Claude Chrome extension could let hackers hijack your online browsing

zeeforce
4 Min Read



  • Koi Security discovers ShadowPrompt zero-click flaw in Claude Code Chrome extension
  • Vulnerability let attackers exploit XSS on claude.ai subdomain to exfiltrate secrets without user interaction
  • Anthropic patched issue in version 1.0.41; researchers warn AI browser assistants are high-value attack targets

A Google Chrome extension for Claude Code, one of the most popular AI tools around, was vulnerable to a zero-click attack which could have allowed malicious actors to exfiltrate sensitive data from the app with the user doing almost nothing risky.

Security researchers Koi Security found the bug, which they dubbed ShadowPrompt, which appears to have come from the browser extension trusting certain websites too much.





Source link

Share This Article
Leave a comment
Optimized by Optimole
Verified by MonsterInsights