Claude Chrome Extension Flaw Leads to Data Theft
cybersecuritynews.com
Wednesday, May 13, 2026
- •Claude in Chrome extension suffers from critical security vulnerability
- •Malicious extensions can hijack AI to access user data
- •Gmail, Drive, and GitHub accounts are exposed to silent data theft
A security vulnerability in the “Claude in Chrome” browser extension enables attackers to hijack the AI assistant. According to the report from May 12, 2026, this flaw allows malicious extensions to silently access and exfiltrate sensitive data from a user’s Gmail, Google Drive, and GitHub accounts. The vulnerability effectively turns the Claude tool into an unauthorized gateway for data theft.