Browser extensions can read your passwords even when you type them manually, warns Reddit thread
iifwe · reddit · 2026-10-01
A Reddit user highlights a widely overlooked agent security issue: when using tools like Claude Code to automate tasks, the Chrome connector can still read passwords via the DOM even if you type them manually with obscured input. If the vendor is breached, a prompt injection occurs, or the model simply errs, credentials could be sent to the cloud. The poster argues most users are unaware of this and questions trusting hyperscaling AI startups with their keys.
More from Safety
- Yacine: Believing AI is conscious is a potent cognitive security vulnerability — yacineMTB · 2026-10-01
- Open-Source Runtime Security Layer Keeps Credentials Out of AI Agents — Technical-Spread-368 · 2026-10-01
- Gary Marcus: LLMs are constitutionally ill-suited to alignment — a defining technical question — GaryMarcus · 2026-10-01
- AI agents leak 13,000+ internal screenshots from 343 orgs to public GitHub repos — The Decoder · 2026-10-01
- Google Cloud to release 31 free hands-on episodes on AI agent security this October — dr_cintas · 2026-10-01
- StepFun employee's X account hacked and used for phishing DMs — StepFun_ai · 2026-10-01