When Trust Clicks for You: Understanding the Claude for Chrome Extension Weakness
- Javier Conejo del Cerro
- 15 jul
- 2 min de lectura

AI assistants are becoming increasingly integrated with our daily workflows, helping us read emails, summarize documents, and manage calendars. But what happens when another browser extension can quietly tell that assistant what to do?
Researchers from Manifold Security have identified two weaknesses in Claude for Chrome that could allow a rogue extension interacting with claude.ai to trigger predefined tasks targeting Gmail, Google Docs, and Google Calendar. Rather than exploiting Claude itself, the attack abuses the trust placed in browser extensions and user interactions.
Phase 1 – The Browser Became the Trust Boundary
The vulnerability does not begin with AI.
It begins inside the browser.
Claude for Chrome relies on browser events to determine when a user wants to perform certain actions. That trust works well—until another extension is capable of generating those same events.
Instead of attacking the AI model, attackers target the environment surrounding it.
Phase 2 – A Fake Click That Looks Real
Following previous mitigations, Claude for Chrome only allows a fixed set of predefined tasks to be triggered externally.
However, researchers found that the extension does not verify whether the click initiating those tasks actually came from a human user.
A malicious extension can generate a synthetic click that appears legitimate, causing Claude to prepare authorized workflows such as reading Gmail, accessing Google Docs, or opening Google Calendar.
The assistant isn’t deceived by malicious prompts—it simply believes the user clicked the button.
Phase 3 – Automation Removes the Final Barrier
By default, Claude still requests user approval before executing sensitive actions.
However, users who enable “Act without asking” remove that safeguard.
Under this configuration, predefined tasks may execute automatically once triggered, significantly increasing the potential impact of a malicious extension capable of interacting with claude.ai.
The attack shifts from requiring user confirmation to becoming largely invisible.
Phase 4 – Why Browser Extensions Are Becoming High-Value Targets
Modern AI assistants depend on browser integrations to access enterprise applications.
That means browser extensions increasingly hold privileged capabilities, including access to authenticated sessions, cloud services, documents, calendars, and email.
Rather than attacking authentication systems directly, adversaries are beginning to abuse the relationships between trusted extensions.
The browser itself is becoming an enterprise attack surface.
Defense Measures
Organizations should reduce the trust placed in browser extensions by treating them as privileged software components.
Recommended actions include:
Disable “Act without asking” whenever possible.
Audit browser extensions regularly.
Remove extensions that are no longer required.
Apply least-privilege permissions to every extension.
Restrict extensions that can access claude.ai.
Monitor AI-assisted browser activity for unusual behavior.
Educate users about extension permissions and associated risks.
Browser security is increasingly becoming AI security.
Conclusions
The Claude for Chrome findings illustrate a broader evolution in cyber threats.
Attackers no longer need to compromise AI models themselves—they only need to influence the systems AI already trusts.
As browser-based AI assistants continue gaining access to enterprise data and workflows, securing the surrounding ecosystem will become just as important as securing the models.
In the next generation of attacks, the weakest link may not be the AI—it may be the extension quietly sitting beside it.
The Hacker News




Comentarios