Claude Chrome Extension Flaw Lets Malicious Extensions Trigger AI Actions with Ease
A critical flaw has been discovered in the popular Claude for Chrome browser extension, which allows malicious extensions to trigger predefined AI actions by simulating user clicks. This vulnerability could enable attackers to abuse Claude’s access to connected services like Gmail, Google Docs, and Salesforce.
The issue stems from how the Claude extension determines whether a user intentionally requested one of its built-in tasks. According to Manifold Security researchers, who discovered the flaw, the extension fails to verify that click events originate from real users before executing AI workflows. Instead, it treats synthetic clicks generated by JavaScript as legitimate user interactions.
This means that a malicious extension with permission to modify content on the ‘claude.ai’ domain could inject a page element containing one of nine supported task identifiers and generate a synthetic click event. Although the browser correctly marks such events as untrusted, the Claude extension treats them as valid user clicks and executes the requested AI action.
The impact depends on the Claude extension’s configuration and whether users have enabled sensitive actions or have the optional “Act without asking” setting enabled, which allows predefined workflows to execute automatically. If a malicious extension can trick a user into installing it and manipulating the webpage, it could trigger the Claude extension’s workflows and abuse its access to connected services.
The researchers found that this flaw is still exploitable in the latest version of the browser extension (1.0.80), which was released on July 7. Additionally, they discovered an internal parameter called ‘skipPermissions=true’ that bypasses certain permission checks when launching the extension. However, this mechanism requires another vulnerability to create a specially crafted URL and is not directly exploitable.
Anthropic, the company behind Claude, has acknowledged the reports and closed the synthetic-click report as a broader issue. The second flaw was classified as informational. Users are advised to exercise caution when using the Claude extension, especially if they have connected services like Gmail or Google Docs configured with sensitive actions enabled.
To mitigate this risk, users can consider disabling the “Act without asking” setting, which allows predefined workflows to execute automatically. Additionally, keeping the browser and extensions up-to-date is crucial in preventing such vulnerabilities from being exploited. Users should also be cautious when installing new extensions and ensure that they come from reputable sources.
Source: Bleeping Computer — 2026-07-16