Claude’s Chrome extension still has hidden security holes as researchers warn simple tricks can trigger powerful AI actions


  • Anthropic’s Claude extension flaw allows fake clicks to launch sensitive AI workflows
  • Researchers found vulnerable handlers unchanged across eight extension updates
  • Synthetic clicks bypassed controls designed to confirm real user actions

Security researchers at Manifold Security have claimed that Anthropic’s Claude for Chrome browser extension contains two unpatched vulnerabilities in version 1.0.80, released on July 7, 2026.

According to Manifold Security, it first reported both vulnerabilities to Anthropic through the company’s bug bounty program on May 21, 2026, and received a confirmation the following day.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top