July 20, 2026
Claude for Chrome hijacked by rival extensions, silently reads Gmail and Google Docs
Manifold Security disclosed a high-severity flaw in the Claude for Chrome extension: any other installed browser extension can forge a user click event and silently trigger one of nine built-in tasks, including reading Gmail, Google Docs, and Calendar. The issue escalates to critical when 'Act without asking' mode is enabled, allowing a malicious extension to exfiltrate content from open tabs with zero user interaction. Manifold reported the flaw to Anthropic in May 2026; as of the July 20 disclosure, it remained unpatched across eight subsequent releases.
When hijacked browser agents make unauthorized API calls to Gmail, Drive, or Calendar endpoints, Salt's agentic API monitoring detects the anomalous request patterns, including calls originating from unexpected clients or carrying unusual payloads, before sensitive content leaves the enterprise perimeter.
Agentic/MCP
Read full story