Any Chrome Extension Just Hijacked Claude. With Zero Permissions.
Key Takeaways
- ClaudeBleed lets any Chrome extension, even one with zero declared permissions, take full control of Claude's browser agent. It can read your Google Drive, send from your Gmail, steal GitHub repos, and wipe the logs. - Anthropic patched the flaw on May 6. A LayerX