Claude desktop extension can be hijacked to send out malware by a simple Google Calendar event

https://www.profitableratecpm.com/f4ffsdxe?key=39b1ebce72f3758345b2155c98e6709c

  • LayerX warns that Claude desktop extensions enable zero-click prompt injection attacks
  • Extensions run unsandboxed with full system privileges, potentially leading to remote code execution
  • Flaw rated CVSS 10/10, seems unresolved

Claude desktop extensions, due to their very nature, can be exploited for rapid zero-click injection attacks that can lead to remote code execution (RCE) and complete system compromise, experts have warned.

Claude is Anthropic’s AI assistant and one of the most popular GenerativeAI models. It offers desktop extensions – MCP servers packaged and distributed through Anthropic’s extensions marketplace, which, when installed, resemble Chrome add-ons.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button