Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

The Security Coverage Gap is a Math Problem

June 26, 2026

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection
News

Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection

Team-CWDBy Team-CWDNovember 5, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Researchers at Koi Security have found that three of Anthropic’s official extensions for Claude Desktop were vulnerable to prompt injection.

The vulnerabilities, reported through Anthropic’s HackerOne program on July 3 and verified as high severity (CVSS 8.9), affected the Chrome, iMessage and Apple Notes connectors.

These extensions are packaged Model Context Protocol (MCP) servers available for download from Anthropic’s marketplace. They allow Claude, the underlying large language model (LLM) which all Anthropic tools rely on, to act on behalf of the user using the web and applications they connect it with.

At first, these extensions look very similar to browser extensions, such as Chrome extensions, providing that same one-click install experience.

Unsanitized Command Injection in Unsandboxed Extensions

While Chrome extensions run in a sandboxed browser process, Claude Desktop extensions run fully unsandboxed on the user’s device, with full system permissions.

“That means they can read any file, execute any command, access credentials and modify system settings. They’re not lightweight plugins – they’re privileged executors bridging Claude’s AI model and your operating system,” the Koi Security researchers wrote in a November 5 report.

The vulnerabilities affecting the three extensions are due to unsanitized command injection, which could turn any benign question to Claude into remote code execution (RCE) on a machine if a malicious actor manages to craft content that get accessed by Claude Desktop.

The assistant, acting in good faith, executes malicious commands because it believes it’s following legitimate instructions.

The attacker could thus be able to collect key information, such as SSH keys, AWS credentials or browser passwords.

These vulnerabilities were fully fixed by Anthropic in version 0.1.9. These fixes were verified by Koi Security on September 19.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleWSUS Exploited, LockBit 5.0 Returns, Telegram Backdoor, F5 Breach Widens
Next Article SideWinder Adopts New ClickOnce-Based Attack Chain Targeting South Asian Diplomats
Team-CWD
  • Website

Related Posts

News

China-Linked Hackers Strike Asian CNI with New Backdoor

June 26, 2026
News

How to Find Hidden Access Risks Inside Your Network

June 26, 2026
News

CMC Releases Analysis and Guidance for Education Sector After Canvas D

June 26, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

The quest for greater tech independence

May 19, 2026

AI-powered financial scams swamp social media

September 11, 2025

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.