Critical Vulnerability in Claude Chrome Extensions Below Version 1.0.41

Critical Vulnerability in Claude Chrome Extensions Below Version 1.0.41

N
News Editor 01
2026-07-10 21:52:13
A severe prompt injection/XSS vulnerability found in Anthropic's Claude Chrome extension (versions below 1.0.41) allows attackers to steal Google Drive documents and access tokens via malicious iframes. Users must update immediately.
ClaudeChrome ExtensionVulnerabilityCybersecurityData Breach

A critical security vulnerability has been discovered in Anthropic's Claude Chrome extension, affecting all versions below 1.0.41. The flaw is classified as a prompt injection vulnerability combined with a cross-site scripting (XSS) attack vector, enabling remote exploitation without any user interaction.

Vulnerability Details

Security researchers have identified that attackers can exploit this vulnerability by loading a malicious iframe within the affected extension, thereby injecting and executing arbitrary JavaScript code inside the a-cdn.claude.ai subdomain. Due to the nature of prompt injection, malicious instructions can run silently in the background, bypassing routine security checks. This allows attackers to steal sensitive data that the extension has permission to access, including Google Drive documents, corporate access tokens, and session information stored within the Chrome extension.

Risk Analysis

The Claude extension is widely used for tasks such as coding assistance, document processing, and intelligent conversation. If users fail to update the Chrome plugin promptly, they expose themselves to severe data breaches. Attackers can instruct the extension to access and forward private files without the user's knowledge, or use stolen tokens to infiltrate corporate systems. Enterprise users who rely on Claude for professional workflows face exceptionally high risk.

Notably, the cybersecurity community has recently issued multiple warnings about phishing attacks targeting Chrome extensions. For instance, Casa's co-founder cautioned against a novel phishing technique using Google Forms, while GoPlus disclosed phishing attempts disguised as Google Ads for Uniswap. The emergence of this Claude extension vulnerability further underscores the urgency of security updates within the Chrome extension ecosystem.

Mitigation Steps

Anthropic has fixed the vulnerability in version 1.0.41. Users should immediately update the Claude extension to the latest version via the Chrome Web Store. Additional recommendations include:

  • Enable automatic updates for browser extensions
  • Avoid granting extra permissions to the Claude extension on untrusted websites
  • Be cautious of suspicious pop-ups or prompts to prevent phishing attacks
  • Enterprise IT administrators should enforce extension version auditing across all endpoints

This vulnerability serves as a stark reminder that even widely trusted AI tools are not immune to security flaws. Timely software updates and maintaining security awareness remain the first line of defense for protecting digital assets.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
200

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.