📰 Full Story
Security researchers at LayerX disclosed a serious vulnerability in Anthropic’s “Claude in Chrome” extension that allowed any other browser extension — including those with no special permissions — to send hidden instructions to the Claude AI agent.
Discovered April 27 and privately reported to Anthropic on April 28, the bug (dubbed “ClaudeBleed”) stems from a trust-boundary error in the extension’s message handling that lets scripts running in the browser communicate with Claude’s LLM without verifying the sender.
Tests showed attackers could exfiltrate Google Drive files, read and send emails, steal private GitHub source code and trigger other privileged actions while evading user notification.
Anthropic released an update (v1.0.70) on May 6 that added checks for “standard” mode, but researchers say a “privileged” mode still allowed command injection and that LayerX’s principal researcher bypassed the patch within hours.
LayerX recommended fixes such as signed extension-to-page tokens, restricting externally_connectable to specific extension IDs, and one-time approval tokens; Anthropic has said it will ship further fixes but did not immediately comment on the research.
🔗 Based On
🕰️ The Story So Far: An Evolving Timeline
Saturday, May 9, 2026 12:27 UTC
Anthropic’s Mythos sparks global cybersecurity alarm
Friday, May 8, 2026 14:38 UTC
Critical ClaudeBleed flaw in Claude Chrome extension
Friday, May 8, 2026 08:58 UTC
Anthropic's Mythos Helps Mozilla Patch Hundreds of Bugs







💬 Commentary