✦ For YouGeopoliticsTechFinanceHealthEnergySportsCulture◆ SN Last Week★ Saved

ShadowPrompt: Zero-Click XSS Flaw Hit Claude Extension

By The Hacker News · Summarized & edited by · 2026-03-26
ShadowPrompt: Zero-Click XSS Flaw Hit Claude Extension

Get the Tech newsletter

Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.

Why it matters: This was a two-vendor trust-boundary failure: Anthropic's subdomain allowlist trusted any `*.claude.ai` origin, and an Arkose Labs CAPTCHA component on that subdomain introduced the XSS. Chaining them turned the Claude extension into an autonomous attack surface capable of stealing tokens and impersonating users in conversations until Anthropic shipped v1.0.41 in late 2025 and Arkose closed its side in February 2026.

Share this story

More tech → Read original →

Get the Tech newsletter

Curated tech stories, every morning. Free.

No spam. Unsubscribe anytime.