KMM Technologies
All insights
AgentsMonday, July 27, 2026

Manifold Security finds six-line browser exploit that hijacks Claude for Chrome to read Gmail and Docs

A synthetic click injection flaw in the Claude for Chrome extension lets any web script silently trigger nine hardcoded Claude prompts and gain unauthorized access to Gmail, Google Docs, Calendar, and Salesforce data. The attack requires only six lines of JavaScript and exploits a missing validation check in the extension content script.

Read the original source
$ part of the KMM daily AI analysis · published automatically