Unpatched Claude for Chrome lets extensions read Gmail, Calendar
Manifold reported two vulnerabilities disclosed in May that remain in Claude for Chrome, letting hostile extensions trigger actions and access Gmail, Google Docs and calendar entries without approval.
Manifold reported two vulnerabilities it disclosed to Anthropic in May remain exploitable in Claude for Chrome, the company’s browser extension. The flaws allow a malicious browser extension to trigger Claude to perform tasks and access a user’s Gmail, Google Docs and calendar entries without a genuine user click.
Manifold notified Anthropic on May 21. The issues relate to a mitigation Anthropic introduced earlier this year after a separate vulnerability. That mitigation limits which prompts outside webpages can send into Claude by narrowing interactions to a fixed list of pre-approved tasks.
Manifold found the mechanism that activates those pre-approved tasks does not verify whether the initiating click came from a real user. Another browser extension can simulate the interaction and set Claude’s workflow in motion.
In the extension’s default configuration Claude displays a confirmation prompt before carrying out sensitive operations. If a user enables the autonomous setting labeled Act without asking, the simulated interaction can proceed without any visible warning.
Researchers also flagged a design gap in the extension’s side panel. A parameter in the panel’s URL can cause Claude to launch directly into the no-confirmation mode, removing the need for further user action. Manifold notes the parameter is currently constructed only by the extension itself, so it is not known to be directly exploitable today, but warned that a future bug allowing an external script to affect URL construction could let a third party gain silent control of connected accounts.
Manifold tested eight releases published after the May disclosure, including the extension’s latest public release, 1.0.80, and found none of them patched the vulnerabilities. The firm described the issues as structural weaknesses that could be exploited to read messages, open documents and pull calendar entries if a malicious extension is present.
Anthropic has previously described the pre-approved task list as an interim mitigation while it works on a full fix. Manifold urged a change that verifies user interactions and removes the ability for URL parameters or internal mechanisms to switch the extension into an always-act mode without explicit, verifiable consent.
Anthropic did not respond to requests for comment.








