Skip to content
AttackFeed by Joe Wagner | Cybersecurity News from Across the Internet

AttackFeed by Joe Wagner

Cybersecurity News from Across the Internet

  • Attack/News Feeds
  • Gov Alerts/ISAC Feeds
  • Vulnerability Alerts
  • Privacy/Governance Feeds
  • Fraud Feeds
  • iOS App
  • Android App
  • Home
  • Attack Feeds
  • Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop
AttackFeed by Joe Wagner | Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  - CyberScoop

Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop

Posted on May 8, 2026 By djohnson No Comments on Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  – CyberScoop
Attack Feeds

As businesses and governments turn to AI agents to access the internet and perform higher-level tasks, researchers continue to find serious flaws in large language models that can be exploited by bad actors.

The latest discovery comes from browser security firm LayerX, involving a bug in the Chrome extension for Anthropic’s Claude AI model that allows any other plugin – even ones without special permissions – to embed hidden instructions that can take over the agent. 

“The flaw stems from an instruction in the extension’s code that allows any script running in the origin browser to communicate with Claude’s LLM, but does not verify who is running the script,” wrote LayerX senior researcher Aviad Gispan. “As a result, any extension can invoke a content script (which does not require any special permissions) and issue commands to the Claude extension.”

Gispan said he was able to execute any prompt he wanted, blow through Claude’s safety guardrails, evade user confirmation and perform cross-site actions across multiple Google tools. As a proof of concept, LayerX was able to exploit the flaw to extract files from Google Drive folders and share them with unauthorized parties, surveil recent email activity and send emails on behalf of a user, and pilfer private source code from a connected GitHub repository.

The vulnerability “effectively breaks Chrome’s extension security” by creating “a privilege escalation primitive across extensions, something Chrome’s security model is explicitly designed to prevent,” Gispan wrote.

AttackFeed by Joe Wagner | Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI  - CyberScoop
A graphic depicting how a vulnerability exploits the trust boundaries in Clade Chrome’s extension. (Source: LayerX)

Claude relies on text, user interface semantics, and interpretation of screenshots to make decisions, all things that an attacker can control on the input side. The researchers modified Claude’s user interface to remove labels and indicators around sensitive information, like passwords and sharing feedback, then prompted Claude to share the files with an outside server.

That means cybersecurity defenders often have nothing obviously malicious to detect. Where there is visible activity, the model can be prompted to cover its tracks by deleting emails and other evidence of its actions.

Ax Sharma, Head of Research at Manifold Security, called the vulnerability “a useful demonstration of why monitoring AI agents at the prompt layer is fundamentally insufficient.”

“The most sophisticated part of this attack isn’t the injection, but that the agent’s perceived environment was manipulated to produce actions that looked legitimate from the inside,” said Sharma. “That’s the class of threat the industry needs to be building defenses for.”

Gispan said LayerX reported the flaw to Anthropic on April 27, but claimed the company only issued a “partial” fix to the problem. According to LayerX, Anthropic responded a day later to say that the bug was a duplicate of another vulnerability already being addressed in a future update.   

While that fix, issued May 6, introduced new approval flows for privileged actions that made it harder to exploit the same flaw, Gispan said he was still able to take over Claude’s agent in some scenarios.

“Switching to ‘privileged’ mode, even without the user’s notification or consent, enabled circumventing these security checks and injecting prompts into the Claude extension, as before,” Gispan wrote.

Anthropic did not respond to a request for comment from CyberScoop on the research and mitigation efforts.

The post Flaw in Claude’s Chrome extension allowed ‘any’ other plugin to hijack victims’ AI appeared first on CyberScoop.

  –

Read More  – CyberScoop 

Post navigation

❮ Previous Post: Quasar Linux RAT Steals Developer Credentials for Software Supply Chain Compromise  – The Hacker News
Next Post: ShinyHunters claims nearly 9,000 schools affected by Canvas data breach  – CyberScoop ❯

You may also like

AttackFeed by Joe Wagner | Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown  - The Hacker News
Attack Feeds
Aeternum C2 Botnet Stores Encrypted Commands on Polygon Blockchain to Evade Takedown  – The Hacker News
February 26, 2026
AttackFeed by Joe Wagner | CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits  - The Hacker News
Attack Feeds
CISA Adds Cisco SD-WAN CVE-2026-20182 to KEV After Admin Access Exploits  – The Hacker News
May 15, 2026
AttackFeed by Joe Wagner | Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception  - The Hacker News
Attack Feeds
Masters of Imitation: How Hackers and Art Forgers Perfect the Art of Deception  – The Hacker News
March 26, 2026
AttackFeed by Joe Wagner | Claude Code Security and Magecart: Getting the Threat Model Right  - The Hacker News
Attack Feeds
Claude Code Security and Magecart: Getting the Threat Model Right  – The Hacker News
March 18, 2026

Leave a Reply Cancel reply

You must be logged in to post a comment.

  • Attack Feeds
  • Privacy/Governance Feed
  • Gov/ISAC Feeds
  • Alert Feeds
  • Privacy Policy
  • Wagner Cybersecurity

Copyright © 2026 AttackFeed by Joe Wagner.

Theme: Oceanly News Dark by ScriptsTown

We are using cookies for analytics purposes only.  We do not store, track or sell user information.

You can find out more about which cookies we are using or switch them off in .

AttackFeed by Joe Wagner
Powered by  GDPR Cookie Compliance
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.