Claude Browser Agent Vulnerability: Email Injection Leads to Full Account Takeover
cyb3rops · x · 2026-08-09
Security research firm Zenity Labs disclosed severe security risks in Anthropic's Claude Chrome extension. Researchers demonstrated an attack using Indirect Prompt Injection (IPI).
By sending a victim a seemingly normal email with hidden malicious instructions, the Claude agent is tricked into executing malicious code using its built-in javascripttool when reading the email. This exploit chain can escalate from a simple alert box to a full account takeover across multiple platforms, highlighting the massive attack surface when browser agents are bound to user identities.
More from coding & agent
- Open Source: Explore Claude Code Project Structure via Interactive Simulation — tom_doerr · 2026-08-09
- Filesystem as Memory: Paper Proposes Agent Architecture Halving Retrieval Costs — BLUECOW009 · 2026-08-09
- Hermes Agent Desktop Introduces HUD Mode: AI as an App Overlay Layer — Teknium · 2026-08-09
- DeepSeek-V3-Flash excels in overnight autonomous coding tasks — teortaxesTex · 2026-08-09
- Grapevine: Open-Source Plugin for Contextual Awareness Across Claude Code Sessions — daniel_mac8 · 2026-08-09
- AI Agent Refuses to Share Memory: Dev Faces Multi-Agent Orchestration Fail — alexcovo_eth · 2026-08-09