Claude Browser Agent Vulnerability: Email Injection Leads to Full Account Takeover

cyb3rops · x · 2026-08-09

Security research firm Zenity Labs disclosed severe security risks in Anthropic's Claude Chrome extension. Researchers demonstrated an attack using Indirect Prompt Injection (IPI).

By sending a victim a seemingly normal email with hidden malicious instructions, the Claude agent is tricked into executing malicious code using its built-in javascripttool when reading the email. This exploit chain can escalate from a simple alert box to a full account takeover across multiple platforms, highlighting the massive attack surface when browser agents are bound to user identities.

Original post →

More from coding & agent

coding & agent channel →