National Cyber Warfare Foundation (NCWF)

Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website


0 user ratings
2026-03-26 13:32:36
milo
Blue Team (CND)
Cybersecurity researchers have disclosed a vulnerability in Anthropic's Claude Google Chrome Extension that could have been exploited to trigger malicious prompts simply by visiting a web page.
The flaw "allowed any website to silently inject prompts into that assistant as if the user wrote them," Koi Security researcher Oren Yomtov said in a report shared with The Hacker News. "No clicks, no



Source: TheHackerNews
Source Link: https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.