🌍 Top Stories🤖 Tech💰 Finance🧬 Health⚡ Energy⚽ Sports🎬 Culture
Tech & Science

Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website

By The Hacker News · 2026-03-26
Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Why it matters: This flaw highlights critical AI extension security risks and the need for robust prompt injection defenses.
A critical zero-click XSS prompt injection vulnerability was discovered in Anthropic's Claude Google Chrome Extension, allowing any website to silently inject malicious prompts into the AI assistant. This flaw could have enabled attackers to manipulate Claude's behavior without user interaction, posing a significant security risk for users of the extension.

Share this story

More tech & science → Read original →

Get tech & science in your inbox

The best stories, summarized daily. Free.

No spam. Unsubscribe anytime.