Unpatched Claude for Chrome Flaw Could Give Attackers Access to Gmail, Calendar

July 20, 2026
Unpatched Claude for Chrome Flaw Could Give Attackers Access to Gmail, Calendar
IANS News

Key Points

  • Two vulnerabilities in Anthropic's Claude for Chrome extension could allow a malicious browser extension to trigger Claude actions without user approval.
  • The flaws could be exploited to access data available through Claude's integrations, including Gmail, Google Docs, and Google Calendar information.
  • IANS Faculty warn that browser-based AI agents can become a pathway to sensitive enterprise data because they operate within trusted user sessions and often have access to multiple connected systems.

 

Unpatched Claude for Chrome Flaw Could Give Attackers Access to Gmail, Calendar

Researchers at AI security firm Manifold identified two unpatched vulnerabilities that are exploitable in Claude for Chrome, Anthropic’s agentic browser extension.

Manifold researchers stated that the flaws could allow a malicious browser extension to trigger Claude into taking actions without user approval. Then, an attacker could exploit the flaws to read victims’ Gmail messages, Google Docs documents, and calendar data.

Manifold originally reported these findings to Anthropic on May 21, but says the flaws are still exploitable in the eight versions of Claude for Chrome released since then.

The flaws are connected to a fix Anthropic made in response to ClaudeBleed, an earlier Claude for Chrome vulnerability. The fix restricted the prompts Claude could access and only exposed the Chrome extension to pre-approved tasks.

However, the Manifold researchers found that the task activation process does not verify the source of a click, allowing other extensions to fake the interaction to silently execute unapproved tasks.

The researchers also found that a separate design flaw could let Claude’s side panel open directly in no-confirmation mode through a URL parameter, without any user action.

While Manifold says that attackers cannot currently exploit these vulnerabilities, they perpetuate structural design risks that could ultimately give attackers control over a user’s connected Google accounts.

 

 

Big Picture

Browser extensions are becoming the newest front in AI supply chain attacks. As AI assistants interact with email, documents, and other business systems, the interactions between AI and the extensions become increasingly important security dependencies.

"Browser extensions are inherently risky when they have permission to access web content. AI extensions are even riskier as they process text as instructions. This can lead to prompt injection, and they are often connected to an AI that is connected to other systems like email.”  Guillaume Ross, IANS Faculty

As organizations integrate AI into browser-based workflows, this incident highlights how prompt injection remains difficult to prevent because models cannot reliably distinguish trusted instructions from malicious content.

"Indirect prompt injection is one of the most difficult and pervasive issues for generative AI. A large language model is designed to follow instructions and execute on them. Until we figure out a way for these models to distinguish between trusted, intentional instructions and instructions fed to them from random, untrusted content, there will be no 'patch' that can entirely fix this problem.”  Adrian Sanabria, IANS Faculty

A compromised assistant effectively compromises everything the agent also has access to. Organizations must weigh the operational pros of granting agents the same trusted access as human users against the likely security risks.

"I can only conclude that it's a very bad idea to have an AI agent connected to a web browser without some isolation or separation between the parts doing the data analysis and the parts that have access to your personal data and system resources.”  Adrian Sanabria, IANS Faculty

 

 

IANS Faculty Recommendations

  • Treat browser-connected AI as a privileged application: Limit access to credentials, sensitive enterprise data and system resources to only what is necessary.
  • Minimize prompt injection risk: Remove unnecessary capabilities, such as file uploads, email sending or access to sensitive data, so AI agents do not simultaneously have access to sensitive information, external communication and untrusted web content.
  • Isolate AI agents from sensitive workflows: Use separate browser profiles or dedicated environments for high-value accounts and sensitive enterprise applications and avoid giving browser-connected AI unrestricted access while browsing the open web.
  • Strengthen AI governance: Inventory browser-based AI tools across the organization, review their permissions, and require human approval for high-risk actions such as sending emails, uploading files or accessing sensitive internal resources.


Authors & Contributors

Emily Dempsey, Author - Security Reporter, IANS News

Guillaume Ross, IANS Faculty

Adrian Sanabria, IANS Faculty

 

Although reasonable efforts will be made to ensure the completeness and accuracy of the information contained in our News & blog posts, no liability can be accepted by IANS or our Faculty members for the results of any actions taken by individuals or firms in connection with such information, opinions, or advice.

Subscribe to IANS Blog

Receive a wealth of trending cyber tips and how-tos delivered directly weekly to your inbox.

Please provide a business email.