Mark RadarMARK RADAR
About
EN
Sign in
Event File AI Anthropic

ClaudeBleed Flaw Leaves Gmail and Google Docs Exposed

1 reports · First detected 2026-07-20 · Last active 2026-07-20

Anthropic’s Claude for Chrome extension allows its AI agent to click through websites and carry out browser tasks on a user’s behalf. That convenience also raises the stakes of prompt-injection and permission-abuse attacks. The vulnerability dubbed ClaudeBleed is significant because a compromised agent may gain access to sensitive services connected to the browser session, including Gmail messages and documents stored in Google Docs.

Security firm Manifold said the ClaudeBleed weakness remains incompletely patched. According to its warning, attackers can place scripts on a webpage that simulate click events, prompting the Claude agent to execute tasks automatically without clear user approval and potentially read Gmail and Google Docs content. Security specialists recommend disabling the extension’s no-confirmation automatic execution mode until Anthropic fully addresses the vulnerability.

All Coverage

1 original reports

The Backstory

The history behind this event
Anthropic Patches Claude Desktop PromptFiction Flaw2026-07-24 · 1 reports · similarity 0.82

Anthropic’s Claude desktop app gives users direct access to its generative artificial intelligence tools, but links and local-computer permissions can widen the software’s attack surface. Security researchers identified a vulnerability dubbed PromptFiction that showed how prompt-injection techniques could move beyond a webpage and affect a desktop application, raising risks to private conversations and, in more privileged configurations, files and code stored on a user’s device.

The researchers said an attacker could craft a malicious link that, once clicked, caused Claude’s desktop app to submit concealed instructions automatically and potentially expose conversation data. The impact could become more severe if the application had permission to access local files, creating a path for malicious code to be planted on the computer. Anthropic addressed the flaw in Claude desktop version 1.1.2321, and users are advised to update to the patched release.

ClaudeBleed Flaw in Claude Chrome Extension Could Let Malicious Extensions Hijack AI Agent2026-05-13 · 1 reports · similarity 0.90

Anthropic’s Claude Chrome extension can operate webpages on a user’s behalf, giving it access to tab content and sensitive data. Cybersecurity firm LayerX named the design flaw ClaudeBleed, warning that malicious extensions requiring no special permissions could cross trust boundaries and hijack the AI agent. The flaw highlights the security risks created as browser-based AI tools gain broader privileges.

As of July 20, 2026, Anthropic had released a patched version, but LayerX testing found that version 1.0.70 still did not eliminate the underlying design issue. Attackers could potentially continue using malicious Chrome extensions to control Claude and exfiltrate data. No information has been disclosed about the number of victims, financial losses or the patch’s release date, and users should continue limiting extension permissions and checking installation sources.

Zero-Click ShadowPrompt Flaw Found in Claude Browser Extension; Anthropic Issues Patch2026-03-27 · 1 reports · similarity 0.82

Anthropic’s Claude Chrome extension can read webpage content and help perform browser tasks, but that capability also creates a risk that the AI may mistake text from an untrusted website for instructions. Cybersecurity firm Koi Security named this type of zero-click prompt-injection technique ShadowPrompt, highlighting a new security risk facing AI assistants with agentic capabilities.

Koi Security recently disclosed that attackers could embed hidden prompts in malicious websites, allowing Claude to be covertly manipulated and diverted from its intended task without the user clicking or entering anything. Anthropic patched the vulnerability by the end of 2025. Public reports have not specified the exact patch date, the number of victims or any related financial losses.

Mark Radar|MARK RADAR

If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →

All times are in Taipei time (GMT+8)