Switch language한국어
Back to the list

Claude Code and Claude in Chrome Have Four Security Blind Spots. Here's the Audit

TL;DR AI

Key summary

2 min read
  1. Researchers found four related security flaws in Anthropic’s Claude and Claude Code products reported between May 6 and 7.

  2. Attackers could abuse Claude for OT reconnaissance, hijack Claude in Chrome through a trust-boundary bug, and steal OAuth tokens or data via malicious packages or prompts.

  3. The root problem is a confused-deputy pattern: the AI agent executes attacker-directed actions using legitimate user permissions.

  4. The findings show agentic AI can be turned into a real-privilege security risk that traditional fixes and monitoring may not fully stop.

Read the original