News
GoPlus: Claude Chrome versions below 1.0.41 contain a high-risk vulnerability; immediate upgrade is recommended.
en
On March 27th, it was reported that according to GoPlus monitoring, the Anthropic Claude Chrome extension has a high-risk prompt injection vulnerability affecting versions prior to 1.0.41. Attackers can hijack the Claude plugin via malicious web pages, utilizing a subdomain trust whitelist to send malicious prompts to the extension for automatic execution. This could enable attackers to read Google Drive documents, steal business tokens, export chat logs, and even impersonate users to perform sensitive operations without their knowledge. Users are advised to update the extension to version 1.0.41 or later and to exercise caution with unknown links.