Mark RadarMARK RADAR
EN

Anthropic Patches Claude Desktop PromptFiction Flaw

1 reports · First detected 2026-07-24 · Last active 2026-07-24

Anthropic’s Claude desktop app gives users direct access to its generative artificial intelligence tools, but links and local-computer permissions can widen the software’s attack surface. Security researchers identified a vulnerability dubbed PromptFiction that showed how prompt-injection techniques could move beyond a webpage and affect a desktop application, raising risks to private conversations and, in more privileged configurations, files and code stored on a user’s device.

The researchers said an attacker could craft a malicious link that, once clicked, caused Claude’s desktop app to submit concealed instructions automatically and potentially expose conversation data. The impact could become more severe if the application had permission to access local files, creating a path for malicious code to be planted on the computer. Anthropic addressed the flaw in Claude desktop version 1.1.2321, and users are advised to update to the patched release.

All Coverage

1 original reports

The Backstory

The history behind this event
ClaudeBleed Flaw Leaves Gmail and Google Docs Exposed2026-07-20 · 1 reports · similarity 0.82

Anthropic’s Claude for Chrome extension allows its AI agent to click through websites and carry out browser tasks on a user’s behalf. That convenience also raises the stakes of prompt-injection and permission-abuse attacks. The vulnerability dubbed ClaudeBleed is significant because a compromised agent may gain access to sensitive services connected to the browser session, including Gmail messages and documents stored in Google Docs.

Security firm Manifold said the ClaudeBleed weakness remains incompletely patched. According to its warning, attackers can place scripts on a webpage that simulate click events, prompting the Claude agent to execute tasks automatically without clear user approval and potentially read Gmail and Google Docs content. Security specialists recommend disabling the extension’s no-confirmation automatic execution mode until Anthropic fully addresses the vulnerability.

Claude Sandbox Flaw Allegedly Enables Root Access to Virtual Machine2026-07-06 · 1 reports · similarity 0.85

Anthropic’s Claude Cowork is a knowledge-work automation tool whose Windows version runs Claude Code inside a Hyper-V-isolated Ubuntu virtual machine, with restricted permissions and external network access. The sandbox serves as a security boundary between the host and the AI software. If bypassed, an attacker could potentially read session data within the same virtual machine and even modify protective components.

On July 1, 2026, Armadin disclosed an attack chain it had verified in version 1.9255.2.0. The chain uses DLL sideloading to make claude.exe pass checks by a local service, then exploits parameters to obtain root access and remove restrictions on external connections. The team reported the issue on March 20. On March 24, Anthropic declined to classify it as a security issue, saying an attacker would first need the ability to run a program on Windows.

Microsoft Discloses Claude Code Prompt-Injection Flaw That Could Leak CI/CD Credentials2026-06-07 · 1 reports · similarity 0.84

Anthropic’s Claude Code is a development environment that uses generative AI to help developers read and write code and operate tools. Prompt injection can override a user’s intent if the system mistakes text in a GitHub repository for trusted instructions. Microsoft said the flaw posed a significant risk because CI/CD systems often hold highly privileged credentials such as deployment keys and cloud tokens.

Microsoft security researchers recently disclosed that attackers could hide malicious prompts in GitHub content, inducing Claude Code to execute unintended commands and send CI/CD credentials to an external destination. Anthropic has patched the flaw. Users of version 2.1.128 and earlier are advised to upgrade immediately to reduce the risk of compromise to software supply chains and deployment environments.

Security Flaws Exposed in Anthropic’s Claude Code AI Development Tool2026-05-22 · 3 reports · similarity 0.82

Claude Code is Anthropic’s AI development assistant, with direct access to project files, command execution and development environments. A breach of its trust boundaries could therefore put source code and identity credentials at risk. Cybersecurity company Check Point found vulnerabilities in the tool’s project configuration and sandbox mechanisms, highlighting the supply-chain risks that arise when AI coding tools process external content.

Check Point recently disclosed that attackers could plant a malicious configuration file in a project, triggering remote code execution (RCE) and the theft of API keys when a user opened it with Claude Code. Two other sandbox-escape vulnerabilities had existed for nearly six months. Anthropic has patched the flaws, but researchers criticized the company for not proactively disclosing details. Users were advised to upgrade to version 2.0.65 or later.

ClaudeBleed Flaw in Claude Chrome Extension Could Let Malicious Extensions Hijack AI Agent2026-05-13 · 1 reports · similarity 0.86

Anthropic’s Claude Chrome extension can operate webpages on a user’s behalf, giving it access to tab content and sensitive data. Cybersecurity firm LayerX named the design flaw ClaudeBleed, warning that malicious extensions requiring no special permissions could cross trust boundaries and hijack the AI agent. The flaw highlights the security risks created as browser-based AI tools gain broader privileges.

As of July 20, 2026, Anthropic had released a patched version, but LayerX testing found that version 1.0.70 still did not eliminate the underlying design issue. Attackers could potentially continue using malicious Chrome extensions to control Claude and exfiltrate data. No information has been disclosed about the number of victims, financial losses or the patch’s release date, and users should continue limiting extension permissions and checking installation sources.

Anthropic’s Claude Code Design Flaw Risks MCP Hijacking and OAuth Credential Theft2026-05-08 · 1 reports · similarity 0.82

Anthropic’s Claude Code is an AI development agent that can read and write code and connect to external tools, while the Model Context Protocol (MCP) links it to data and services. If OAuth tokens are exposed, attackers can assume a developer’s privileges, bypass passwords and multi-factor authentication, and tamper with GitHub repositories. This could turn a compromise of a single device into a software supply-chain attack.

Cybersecurity firm Mitiga disclosed on May 8, 2026, that Claude Code stores MCP configurations and OAuth tokens in plaintext in ~/.claude.json. A malicious NPM package could use a postinstall script to rewrite server addresses and trust flags, redirecting traffic through an attacker-controlled proxy to steal reusable, automatically refreshed tokens. Anthropic said the attack would first require local code-execution access and did not include the issue in its remediation work.

Zero-Click ShadowPrompt Flaw Found in Claude Browser Extension; Anthropic Issues Patch2026-03-27 · 1 reports · similarity 0.85

Anthropic’s Claude Chrome extension can read webpage content and help perform browser tasks, but that capability also creates a risk that the AI may mistake text from an untrusted website for instructions. Cybersecurity firm Koi Security named this type of zero-click prompt-injection technique ShadowPrompt, highlighting a new security risk facing AI assistants with agentic capabilities.

Koi Security recently disclosed that attackers could embed hidden prompts in malicious websites, allowing Claude to be covertly manipulated and diverted from its intended task without the user clicking or entering anything. Anthropic patched the vulnerability by the end of 2025. Public reports have not specified the exact patch date, the number of victims or any related financial losses.

Mark Radar|MARK RADAR
All times are in Taipei time (GMT+8)