Claude’s Chrome extension still has hidden security flaws as researchers warn simple tricks can trigger powerful AI actions


  • Anthropic Claude Extension Flaws Allow False Clicks to Launch Sensitive AI Workflows
  • Researchers found vulnerable handlers unchanged in eight extension updates
  • Synthetic clicks bypassed controls designed to confirm real user actions

Security researchers at Manifold Security have claimed that Anthropic’s Claude browser extension for Chrome contains two unpatched vulnerabilities in version 1.0.80, released on July 7, 2026.

According to Manifold Security, the company first reported the two vulnerabilities to Anthropic through the company’s bug bounty program on May 21, 2026, and received an acknowledgment the next day.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top