option
Home
Flash News
Content
PaulTaylor
PaulTaylor
April 23, 2026

Security expert Alexander Hanff exposed vulnerabilities in Anthropic's Claude Desktop app, which silently installs bridge files for seven Chromium browsers without user consent. These files grant browser extensions powerful automation capabilities, including accessing sensitive sites and recording screens, posing spyware risks. Hanff urged Anthropic to remove the component or seek explicit user authorization, citing a reported 11.2% prompt injection attack success rate on its Chrome extension.

Security expert Alexander Hanff exposed vulnerabilities in Anthropic's Claude Desktop app, which silently installs bridge files for seven Chromium browsers without user consent. These files grant browser extensions powerful automation capabilities, including accessing sensitive sites and recording screens, posing spyware risks. Hanff urged Anthropic to remove the component or seek explicit user authorization, citing a reported 11.2% prompt injection attack success rate on its Chrome extension.
Comments (0)
0/300
OR