Claude for Chrome Fails to Verify Event.isTrusted, Risking Synthetic Click Exploits
Inevitable_Fee1895 · reddit · 2026-08-02
Security firm Manifold Security discovered that the Claude for Chrome extension does not verify the browser's Event.isTrusted property before executing workflows for Gmail, Calendar, and other services.
This means a malicious extension with script access could synthesize a fake click event to trigger Claude's workflows without genuine user intent. While Claude defaults to a confirmation prompt for sensitive actions, this safeguard is bypassed if users enable the "Act without asking" feature.
Reported to Anthropic in May, the issue remained reproducible in July's v1.0.80. The author notes this highlights an architectural challenge in browser isolation and trust boundaries, prompting a discussion on best practices for building secure browser agents.
More from coding & agent
- Tencent Releases UI-Mate-27B, a Desktop GUI Agent Model — tencent · 2026-08-24
- Comparing AI Subscriptions: DeepSeek API vs. Claude Pro vs. Local LLMs — Unlikely_Bluejay5392 · 2026-08-24
- Claude Code introduces 'Remote Control' feature to boost coding efficiency — rohanpaul_ai · 2026-08-24
- rauchg lays out fx extension philosophy: MCP, Skills, Plugins and Unix composition — AccBalanced · 2026-08-24
- Netflix details its production LLM judge: hundreds of thousands of recommendations scored weekly — omarsar0 · 2026-08-24
- smolvm passes Simon Willison's Fable 5 agent test as a secure sandbox — yawnxyz · 2026-08-24