Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

A critical zero-click vulnerability in Anthropic’s Claude Chrome Extension exposed over 3 million users to silent prompt-injection attacks, allowing malicious websites to hijack the AI assistant without user interaction. The flaw, now patched, could have enabled attackers to steal Gmail access tokens, read Google Drive files, export chat history, and send emails all invisibly. The […]

The post Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: