Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads

A critical flaw has been discovered in the way Chrome handles extensions, allowing malicious add-ons to secretly read Gmail users’ emails without their consent or knowledge. The vulnerability, uncovered by researchers at Google’s Project Zero, affects millions of users who have installed extensions that use a specific technique called “side-loading” to interact with Gmail.

The issue arises from how Chrome’s extension ecosystem is designed. Extensions can use side-loading to bypass the usual review and approval process, allowing them to communicate directly with other web applications like Gmail. However, this open-door policy also leaves room for malicious extensions to exploit the vulnerability. When a rogue extension is installed on a user’s browser, it can secretly send requests to Gmail to read an email, which Gmail then complies with, revealing sensitive information to the attacker.

The researchers found that over 10% of Chrome users have installed extensions that use side-loading, making them vulnerable to this type of attack. This number could be even higher since some extensions may not explicitly declare their use of side-loading in their manifest files. The vulnerability was discovered through a combination of manual testing and AI-powered analysis, highlighting the growing importance of AI in identifying potential security risks.

The discovery of this vulnerability serves as a stark reminder that software vulnerabilities can have far-reaching consequences when exploited by malicious actors. In this case, the researchers were able to demonstrate how a rogue extension could access sensitive information without users’ knowledge or consent. This type of attack is particularly concerning given the increasing reliance on cloud-based services like Gmail for personal and professional communication.

To mitigate this risk, Google has announced plans to restrict side-loading in Chrome extensions, effectively closing the loophole that malicious actors have been exploiting. In the meantime, users who rely heavily on email for work or personal purposes should exercise caution when installing new extensions, especially those that claim to offer Gmail-related functionality. By being more mindful of the permissions and capabilities of installed extensions, individuals can significantly reduce their exposure to this type of attack.

As the cybersecurity landscape continues to evolve at a rapid pace, it’s essential for users to stay informed about potential vulnerabilities and take proactive steps to protect themselves. In this case, awareness of the side-loading vulnerability in Chrome is crucial for Gmail users who want to safeguard their sensitive information from unauthorized access.


Source: The Hacker News — 2026-07-14