Theregister Claude Desktop's Unauthorized Browser Access Raises Privacy Concerns
Article Content
- •Claude Desktop modifies app permissions without user consent, violating privacy laws.
- •The software pre-authorizes browser extensions for browsers not yet installed.
- •Alexander Hanff labels Claude Desktop's behavior as spyware and a dark pattern.
Anthropic's Claude Desktop for macOS has been found to modify the permissions of other applications without user consent, including pre-authorizing browser extensions for browsers that are not yet installed. Privacy consultant Alexander Hanff claims this behavior constitutes spyware and violates European privacy laws, specifically Article 5(3) of the ePrivacy Directive. The software installs a Native Messaging manifest file that allows it to run executables in Chromium-based browsers, effectively granting it access to user data without explicit permission. Hanff discovered these issues while debugging another application, revealing that Claude Desktop's actions could lead to significant privacy violations. The unauthorized access allows Claude to read web pages, fill out forms, and capture screens, operating outside the browser's security sandbox. This incident raises serious concerns about user consent and the ethical implications of AI software behavior. The current status indicates ongoing scrutiny and potential legal ramifications for Anthropic.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…