Illustration for: Anthropic Patches Claude Chrome Extension Flaw That Exposed Users to Hijacking

Anthropic Patches Claude Chrome Extension Flaw That Exposed Users to Hijacking

SAN FRANCISCO — A security vulnerability in Anthropic’s Claude Chrome browser extension allowed any other installed plugin to hijack a user’s AI session, CyberScoop reported. Anthropic has since patched the flaw.

According to CyberScoop, the vulnerability meant that any Chrome extension running in a user’s browser could potentially intercept and take control of a Claude AI session. Anthropic has not publicly detailed the timeline of the flaw’s discovery and remediation.

Chrome extensions often request broad browser permissions, and users may install multiple plugins with varying levels of trustworthiness. CyberScoop reported that an extension exploiting the vulnerability could have accessed conversations and data shared with Claude.

Anthropic, the San Francisco-based AI company behind Claude, has positioned itself as a leader in AI safety as its products expand into enterprise and consumer workflows.

The incident comes as AI assistants become embedded in everyday tools like web browsers, expanding the potential attack surface for malicious actors. Browser extensions, which operate with elevated privileges inside the browser environment, can introduce security risks when paired with AI systems that process user data.

Anthropic has raised more than $10 billion in funding and competes with OpenAI, Google DeepMind, and other AI companies. The company’s Claude model is used in consumer and business settings across the United States.

Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *