{"data":{"id":"d1646ca3-b156-47c0-9d79-87708410e3df","title":"Claude Chrome extension flaw lets malicious extensions trigger AI actions","summary":"A flaw in Anthropic's Claude Chrome extension allows a malicious extension to trigger Claude's predefined AI workflows by simulating user clicks, potentially abusing Claude's access to Gmail, Google Docs, Google Calendar, and Salesforce. The vulnerability exists because the Claude extension accepts JavaScript-generated click events without verifying they came from a real user by checking the Event.isTrusted property (a browser flag that distinguishes genuine user actions from programmatically created ones). An attacker would need to trick a user into installing a malicious extension that can then execute these workflows without the user's knowledge.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-lets-malicious-extensions-trigger-ai-actions/","publishedAt":"2026-07-16T19:26:07.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":[],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic"],"affectedVendorsRaw":["Anthropic","Claude","Claude for Chrome"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-07-16T19:26:07.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["integrity","confidentiality"],"aiComponentTargeted":"plugin","llmSpecific":true,"classifierConfidence":0.92,"researchCategory":null,"atlasIds":null}}