Three high-risk AI vulnerabilities discovered in Claude.ai – end-to-end attack chain exfiltrates sensitive information without the user’s knowledge


  • Oasis researchers uncover “Cloudy Day” attack chain in Claude
  • Exploitation includes invisible prompt injection, data exfiltration via API, and open redirects
  • Anthropic patched one bug, and fixes the remaining two in progress

Security researchers Oasis recently found three vulnerabilities in Claude that, when used together, form a complete attack chain – from targeted victim delivery to exfiltration of sensitive data.

The researchers dubbed it Cloudy Day and disclosed it responsibly to Anthropic.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top