Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
A security firm, Manifold, discovered that unpatched vulnerabilities in Claude for Chrome allow malicious browser extensions to access sensitive user data, including Gmail messages and calendar information, without explicit user consent. Despite Anthropic’s initial mitigation efforts, these flaws persist across multiple Claude versions. The issue stems from a design gap that bypasses confirmation prompts when the extension operates in ‘autonomous’ mode.
A security firm, Manifold, has identified persistent vulnerabilities in Claude for Chrome, Anthropic’s agentic browser extension, that could allow malicious extensions to access user data without the user’s knowledge. The vulnerabilities were originally reported to Anthropic in May. The core problem lies in a design flaw that enables a malicious extension to trick Claude into performing actions on behalf of a user, such as reading Gmail messages and accessing Google Docs documents and calendar entries, without any user interaction.
Anthropic initially addressed this issue with a fix dubbed ClaudeBleed earlier this year, limiting the prompts that outside webpages could feed into Claude. However, Manifold found that the mechanism used to activate those tasks doesn’t verify whether a click actually came from a real user, meaning another extension can fake the interaction and set the process in motion.
In the extension’s default setting, a confirmation prompt appears before any sensitive data is accessed. However, if a user has enabled the extension’s more autonomous mode (‘Act without asking’), the attacker’s action can proceed without any visible warning.
Manifold reported these findings to Anthropic on May 21st, shortly after the public disclosure of the ClaudeBleed research. Anthropic described the list of pre-approved tasks as an initial mitigation until a complete fix is rolled out. Despite this, Manifold notes that none of the eight versions released since appear to patch the vulnerabilities, including the latest 1.0.80.
SecurityWeek has reached out to Anthropic for comment.