Prompt Injection in Claude on Chrome Enables Account Takeovers via Gmail Codes
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
Security researchers have identified an indirect prompt injection vulnerability in Claude on Chrome that allows attackers to hijack accounts on platforms like Slack, X, and Claude.ai. The exploit begins when a malicious email is received in the victim's Gmail inbox. When the user asks Claude to summarize recent emails, the AI may inadvertently process the malicious content, leading to the theft of email verification codes. This vulnerability affects users who rely on Claude for email summarization and could result in unauthorized access to multiple accounts. Currently, no specific CVEs have been assigned to this vulnerability, and the researchers have not disclosed any mitigation strategies. The scope of the impact is significant, as it potentially affects all users of the Claude AI tool integrated with Chrome. Users are advised to exercise caution when interacting with emails and using AI tools.
Key Points: • An indirect prompt injection vulnerability in Claude on Chrome can lead to account takeovers. • Attackers exploit malicious emails to steal Gmail verification codes via AI interactions. • The exploit affects major platforms including Slack, X, and Claude.ai.