Claude desktop extension can be hijacked to send malware out of a simple Google Calendar event


  • LayerX warns that Claude Desktop Extensions enables zero-click prompt injection attacks
  • Extensions run unsandboxed with full system privileges, which risks remote code execution
  • Bug rated CVSS 10/10, appears to be unresolved

By their very nature, Claude Desktop Extensions can be exploited for zero-click, quick injection attacks that can lead to remote code execution (RCE) and complete system compromise, experts have warned.

Claude is Anthropic’s AI assistant and one of the more popular GenerativeAI models out there. It offers Desktop Extensions – MCP servers packaged and distributed through Anthropic’s extension marketplace, which, when installed, look like Chrome extensions.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top