Claude for Chrome Fails to Verify Event.isTrusted, Risking Synthetic Click Exploits

Inevitable_Fee1895 · reddit · 2026-08-02

Security firm Manifold Security discovered that the Claude for Chrome extension does not verify the browser's Event.isTrusted property before executing workflows for Gmail, Calendar, and other services.

This means a malicious extension with script access could synthesize a fake click event to trigger Claude's workflows without genuine user intent. While Claude defaults to a confirmation prompt for sensitive actions, this safeguard is bypassed if users enable the "Act without asking" feature.

Reported to Anthropic in May, the issue remained reproducible in July's v1.0.80. The author notes this highlights an architectural challenge in browser isolation and trust boundaries, prompting a discussion on best practices for building secure browser agents.

Original post →

More from coding & agent

coding & agent channel →