Claude desktop extension can be hijacked to send malware out of a simple Google Calendar event
LayerX warns that Claude Desktop Extensions enables zero-click prompt injection attacks Extensions run unsandboxed with full system privileges, which risks remote code execution Bug rated CVSS 10/10, appears to be unresolved By their very nature, Claude Desktop Extensions can be exploited for zero-click, quick injection attacks that can lead to remote code execution (RCE) and […]









