‘No clicks, no permission requests. Just visit a page and an attacker completely controls your browser’: Experts warn Claude’s Chrome extension could allow hackers to hijack your online browsing


  • Koi Security discovers ShadowPrompt zero-click flaw in Claude Code Chrome extension
  • A vulnerability allows attackers to exploit XSS on the claude.ai subdomain to exfiltrate secrets without user interaction.
  • Corrected problem of anthropogenic origin in version 1.0.41; researchers warn that AI navigation assistants are high-value attack targets

A Google Chrome extension for Claude Code, one of the most popular AI tools, was vulnerable to a zero-click attack that could have allowed bad actors to exfiltrate sensitive data from the app without the user doing almost anything risky.

Security researchers Koi Security discovered the bug, which they dubbed ShadowPrompt, which appears to come from a browser extension that trusts certain websites too much.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top