<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn" -->

---
title: Claude for Chrome extension has two unpatched security...
description: Two unpatched security vulnerabilities exist in Anthropic&#x27;s Claude for Chrome extension (v1.0.80). The first flaw is in the click handler, which fails to...
canonical: https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Claude for Chrome extension has two unpatched security flaws that let malicious extensions abuse AI access | daily.dev
og:description: Two unpatched security vulnerabilities exist in Anthropic&#x27;s Claude for Chrome extension (v1.0.80). The first flaw is in the click handler, which fails to...
og:url: https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn
og:image: https://api.daily.dev/og/posts/Ec2WSfxWn.png
og:image:alt: Claude for Chrome extension has two unpatched security flaws that let malicious extensions abuse AI access
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude for Chrome extension has two unpatched security flaws that let malicious extensions abuse AI access

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

Two unpatched security vulnerabilities exist in Anthropic's Claude for Chrome extension (v1.0.80). The first flaw is in the click handler, which fails to validate the browser's Event.isTrusted property, allowing malicious extensions to inject fake click events and trigger Claude workflows that access Gmail, Google Docs, Google Calendar, and Salesforce data. The second flaw is a URL parameter (?skipPermissions=true) that bypasses normal permission checks. Both were reported to Anthropic in May via bug bounty, but Anthropic closed the tracking issue as resolved without actually fixing either vulnerability.

## Content

Two security vulnerabilities in Anthropic's Claude for Chrome extension remain unpatched despite being reported in May, according to researchers at Manifold Security. Both bugs allow malicious browser extensions to abuse the AI's elevated privileges.

## How the attacks work

The first flaw is straightforward: the extension's click handler doesn't verify the browser's `Event.isTrusted` property. That property exists specifically to distinguish real user clicks from synthetic ones injected by scripts. Claude for Chrome ignores it entirely, which means any malicious extension with access to the claude.ai domain can simulate a click and trigger predefined AI workflows - ones that can read Gmail, Google Docs, Google Calendar, and Salesforce data.

Manifold Security demonstrated the exploit in six lines of JavaScript. The proposed fix is one line.

The second flaw involves a URL parameter: `?skipPermissions=true`. Loading the extension with this parameter puts it into a privileged mode that bypasses normal permission checks. It's less immediately dangerous than the first bug, but it creates a latent attack surface for future exploits.

## What's actually at risk

The attack is constrained to nine predefined tasks the extension supports, and it requires a victim to have already installed a malicious extension. That's a real prerequisite, not a trivial one. But if those conditions are met, the attacker gets AI-assisted access to a fairly sensitive slice of someone's digital life.

## Where things stand

Manifold Security reported both vulnerabilities through Anthropic's bug bounty program. Anthropic marked the tracking issue as "resolved." As of version 1.0.80, released July 7, both bugs remain exploitable.

This is part of a broader pattern worth paying attention to: as AI assistants gain deeper integration with browsers and productivity tools, the attack surface they introduce grows alongside their usefulness. An extension that can read your Gmail on your behalf is also an extension that can be tricked into reading your Gmail on someone else's behalf.

## Similar posts on daily.dev

- [Claude in Chrome is taking orders from the wrong extensions](https://daily.dev/posts/claude-in-chrome-is-taking-orders-from-the-wrong-extensions-fxzui5dan) · CSO Online · 1 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#devtools](https://daily.dev/tags/devtools), [#claude](https://daily.dev/tags/claude), [#anthropic](https://daily.dev/tags/anthropic)

[View this post on daily.dev](https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Claude for Chrome extension has two unpatched security flaws that let malicious extensions abuse AI access","url":"https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn"},"datePublished":"2026-07-17T00:18:09.154Z","dateModified":"2026-07-20T07:30:50.045Z","description":"Two unpatched security vulnerabilities exist in Anthropic's Claude for Chrome extension (v1.0.80). The first flaw is in the click handler, which fails to...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e9b87affb4730dc1f0877a07f078c693?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/e9b87affb4730dc1f0877a07f078c693?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Collections","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Collections","logo":"https://media.daily.dev/image/upload/s--fk_6ycEi--/f_auto,q_auto/v1780996001/logos/collections?_a=BAMAMiWQ0","url":"https://daily.dev/sources/collections"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/claude-for-chrome-extension-has-two-unpatched-security-flaws-that-let-malicious-extensions-abuse-ai--ec2wsfxwn","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,devtools,claude,anthropic","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Collections","item":"https://daily.dev/sources/collections"},{"@type":"ListItem","position":3,"name":"Claude for Chrome extension has two unpatched security flaws that let malicious extensions abuse AI access"}]}
```

