Claude Code and Claude in Chrome Have Four Security Blind Spots. Here's the Audit

TL;DR AI
2 min readKey summary
Researchers found four related security flaws in Anthropic’s Claude and Claude Code products reported between May 6 and 7.
Attackers could abuse Claude for OT reconnaissance, hijack Claude in Chrome through a trust-boundary bug, and steal OAuth tokens or data via malicious packages or prompts.
The root problem is a confused-deputy pattern: the AI agent executes attacker-directed actions using legitimate user permissions.
The findings show agentic AI can be turned into a real-privilege security risk that traditional fixes and monitoring may not fully stop.
