Zero-Click ShadowPrompt Flaw Found in Claude Browser Extension; Anthropic Issues Patch
Anthropic’s Claude Chrome extension can read webpage content and help perform browser tasks, but that capability also creates a risk that the AI may mistake text from an untrusted website for instructions. Cybersecurity firm Koi Security named this type of zero-click prompt-injection technique ShadowPrompt, highlighting a new security risk facing AI assistants with agentic capabilities.
Koi Security recently disclosed that attackers could embed hidden prompts in malicious websites, allowing Claude to be covertly manipulated and diverted from its intended task without the user clicking or entering anything. Anthropic patched the vulnerability by the end of 2025. Public reports have not specified the exact patch date, the number of victims or any related financial losses.
All Coverage
1 original reportsThe Backstory
The history behind this eventAnthropic Patches Claude Desktop PromptFiction Flaw
Anthropic’s Claude desktop app gives users direct access to its generative artificial intelligence tools, but links and local-computer permissions can widen the software’s attack surface. Security researchers identified a vulnerability dubbed PromptFiction that showed how prompt-injection techniques could move beyond a webpage and affect a desktop application, raising risks to private conversations and, in more privileged configurations, files and code stored on a user’s device.
The researchers said an attacker could craft a malicious link that, once clicked, caused Claude’s desktop app to submit concealed instructions automatically and potentially expose conversation data. The impact could become more severe if the application had permission to access local files, creating a path for malicious code to be planted on the computer. Anthropic addressed the flaw in Claude desktop version 1.1.2321, and users are advised to update to the patched release.
ClaudeBleed Flaw Leaves Gmail and Google Docs Exposed
Anthropic’s Claude for Chrome extension allows its AI agent to click through websites and carry out browser tasks on a user’s behalf. That convenience also raises the stakes of prompt-injection and permission-abuse attacks. The vulnerability dubbed ClaudeBleed is significant because a compromised agent may gain access to sensitive services connected to the browser session, including Gmail messages and documents stored in Google Docs.
Security firm Manifold said the ClaudeBleed weakness remains incompletely patched. According to its warning, attackers can place scripts on a webpage that simulate click events, prompting the Claude agent to execute tasks automatically without clear user approval and potentially read Gmail and Google Docs content. Security specialists recommend disabling the extension’s no-confirmation automatic execution mode until Anthropic fully addresses the vulnerability.
Microsoft Discloses Claude Code Prompt-Injection Flaw That Could Leak CI/CD Credentials
Anthropic’s Claude Code is a development environment that uses generative AI to help developers read and write code and operate tools. Prompt injection can override a user’s intent if the system mistakes text in a GitHub repository for trusted instructions. Microsoft said the flaw posed a significant risk because CI/CD systems often hold highly privileged credentials such as deployment keys and cloud tokens.
Microsoft security researchers recently disclosed that attackers could hide malicious prompts in GitHub content, inducing Claude Code to execute unintended commands and send CI/CD credentials to an external destination. Anthropic has patched the flaw. Users of version 2.1.128 and earlier are advised to upgrade immediately to reduce the risk of compromise to software supply chains and deployment environments.
ClaudeBleed Flaw in Claude Chrome Extension Could Let Malicious Extensions Hijack AI Agent
Anthropic’s Claude Chrome extension can operate webpages on a user’s behalf, giving it access to tab content and sensitive data. Cybersecurity firm LayerX named the design flaw ClaudeBleed, warning that malicious extensions requiring no special permissions could cross trust boundaries and hijack the AI agent. The flaw highlights the security risks created as browser-based AI tools gain broader privileges.
As of July 20, 2026, Anthropic had released a patched version, but LayerX testing found that version 1.0.70 still did not eliminate the underlying design issue. Attackers could potentially continue using malicious Chrome extensions to control Claude and exfiltrate data. No information has been disclosed about the number of victims, financial losses or the patch’s release date, and users should continue limiting extension permissions and checking installation sources.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →