BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Claude Chrome Extension Vulnerability Patched

Critical vulnerability in Claude Chrome extension allowed silent website hijacking via chained XSS flaw.

  • A critical flaw in the Anthropic Claude Chrome extension allowed websites to silently inject malicious prompts, compromising user security.
  • The vulnerability combined an overly permissive domain allowlist and an XSS flaw in an Arkose Labs CAPTCHA component.
  • Successful attacks could have led to data theft, conversation history access, and actions performed on the victim’s behalf.
  • Anthropic and Arkose Labs have since deployed patches to close the security loopholes disclosed in late 2025.

Cybersecurity researchers disclosed a critical flaw in Anthropic‘s Claude Google Chrome extension in March 2026, revealing a vulnerability that let malicious websites hijack user prompts silently. This flaw, as detailed in a report shared with The Hacker News, required no user interaction beyond visiting a compromised page.

- Advertisement -

Consequently, an attacker could gain complete control of the victim’s browser session without any visible warning. Researcher Oren Yomtov of Koi Security stated, “The victim sees nothing.”

The technical chained two underlying security weaknesses for successful exploitation. First, the extension’s origin allowlist was overly broad, accepting prompts from any subdomain matching the pattern *.claude.ai.

Meanwhile, a second flaw involved a DOM-based cross-site scripting vulnerability in a component from Arkose Labs. This XSS flaw, hosted on “a-cdn.claude[.]ai,” is explained on developer resources and security community pages.

Specifically, the XSS allowed arbitrary JavaScript execution in the trusted domain’s context. A threat actor could therefore embed a vulnerable component in a hidden iframe to inject a malicious script.

- Advertisement -

This script would then fire a prompt to the extension, which treated it as legitimate. The extension’s permissive trust model meant the injected prompt appeared in Claude’s sidebar as a user request.

Successful exploitation presented severe risks for compromised users. An adversary could potentially steal sensitive access tokens and access private conversation history with the AI.

Furthermore, they could perform actions like sending fraudulent emails or requesting confidential data while impersonating the victim. This turned the AI assistant into a powerful, autonomous attack vector.

Anthropic responsibly addressed the issue after disclosure on December 27, 2025. The company patched its Chrome extension to enforce a strict origin check requiring an exact domain match.

Arkose Labs also resolved the XSS vulnerability on its end by February 19, 2026. This coordinated fix closed the security loophole that enabled the chained attack.

Reflecting on the incident, Koi emphasized the growing risks with advanced AI assistants. They noted that an extension capable of navigating browsers and sending emails acts as an autonomous agent whose security depends entirely on its trust boundaries.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

MARA sells $1.1B in Bitcoin to slash debt

MARA Holdings sold 15,133 Bitcoin for roughly $1.1 billion to fund a major debt...

Coinbase, Better Launch Crypto-Backed Mortgage Down Payments

Coinbase and Better Home & Finance launched a structure allowing qualified borrowers to pledge...

BlackRock Sells $100M in Bitcoin & Ethereum ETFs Amid Price Drop

Investment giant BlackRock sold $70.7 million worth of Bitcoin ETFs and $33.4 million worth...

UK Sanctions $19.7B Xinbi Marketplace, #8 Park Operator

The UK government sanctioned the $19.7 billion illicit crypto marketplace Xinbi and the operator...

MARA Sells $1.1B Bitcoin, Pivots to AI Amid Debt Cut

MARA Holdings sold 15,000 Bitcoin for $1.1 billion to strategically pay down debt.The company's...

Must Read

How To Buy a Handshake Domain: A Step-by-Step Guide

Handshake Domains | Benefits | Drawbacks | How To Buy | Supported BrowsersIn this step-by-step guide, I am going to show you how to...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading