‘No clicks, no permission prompts. Just Visit a Page and an Attacker Takes Complete Control of Your Browser’: Experts Warn Claude Chrome Extension Can Let Hackers Hijack Your Online Browsing


  • Koi Security detects ShadowPrompt zero-click flaw in the Claude Code Chrome extension
  • Vulnerability allows attackers to exploit XSS on the claude.ai subdomain to exfiltrate secrets without user interaction
  • Anthropic fixed issue in version 1.0.41; researchers warn that AI browser assistants are high-value attack targets

A Google Chrome extension for Claude Code, one of the most popular AI tools, was vulnerable to a zero-click attack that could have allowed malicious actors to exfiltrate sensitive data from the app while the user did almost nothing risky.

Security researchers Koi Security found the flaw, which they dubbed ShadowPrompt, which appears to come from the browser extension relying too much on certain websites.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top