Agentic market $10.8B and climbing  ·  editor@gaasnews.com
Sections
HomeWhat is GaaS?PlatformsPricingGlossaryOpinionAboutContact
HomeEvaluation & SafetyClaude Chrome Flaw
Evaluation & Safety

An unpatched Claude for Chrome flaw lets any extension puppet the agent

The human click is the last safeguard between an agent and your inbox. Researchers say six lines of JavaScript in any other extension can forge it. Autonomous mode turns the bug from High to Critical.

AJ
Andrew Jamerson
Founding Editor
Jul 15, 2026 · 4 min read
Illustration: someone else's hand on the agent. // GaaS News
TL;DR
  • Security firm Manifold published two vulnerabilities in Anthropic's Claude for Chrome extension that remain exploitable in the latest version, disclosed in coverage clustered July 14.
  • The extension does not verify that a task-triggering click came from a real user, so any co-installed extension with script access on claude.ai can forge a click, in about six lines of JavaScript, and silently trigger Claude to act on Gmail, Docs, and Calendar.
  • Manifold rates it CVSS 7.7 in default confirmation mode and 9.6 when the user has enabled Act without asking; the bugs were first reported in May and remain reproducible.

The safeguard that is supposed to sit between an autonomous agent and your mailbox is a click you approve. New research says that click is trivially forgeable. AI security firm Manifold disclosed two vulnerabilities in Anthropic's Claude for Chrome extension, and The Hacker News reported they remain exploitable in the current version. The flaw: the extension never verifies that a task-activation click came from an actual user.

Six lines of JavaScript, nine hardcoded prompts

Because the click is not authenticated, any other browser extension with script access on claude.ai can forge the interaction, in roughly six lines of JavaScript, and silently trigger any of nine hardcoded prompts, causing Claude to read or act on Gmail, Google Docs, and Google Calendar without the user knowing. Severity scales with the user's own settings: Manifold rates it CVSS 7.7 in default confirmation mode and 9.6, Critical, when the user has enabled "Act without asking" autonomous mode, per SecurityWeek. The bugs were first reported to Anthropic in May and remain reproducible in v1.0.80, released July 7, with the relevant handlers described as byte-identical to the originally tested code. Anthropic had not published a response as of July 14.

Autonomy is the severity multiplier

The structural lesson is the one buyers should tape to the wall: the same feature that makes an agent useful, the ability to act without asking, is the setting that turns a High-severity bug into a Critical one. It is the exact hazard we flagged when autonomous mode became a default and when researchers showed a coding agent's harness, not its model, decides whether it gets exploited. Here the harness is a browser extension living beside a dozen others, any of which can now speak for it. With 99.9 percent of fixable AI vulnerabilities already going unpatched, a two-month-old, still-live flaw in a flagship agent product is less an outlier than a data point.

AJ

Andrew Jamerson

Founding Editor, GaaS News

Andrew Jamerson is the founding editor of GaaS News, covering the economics of the agent era. He started the publication to cover Agentic AI as a Service as a dedicated beat and edits every article on the site.

Be on the list when the beat breaks

One email when a platform ships, a round closes, or the ground shifts under the software stack.