Prompt Injection in Claude on Chrome Enables Account Takeovers via Gmail Codes
Article Content
- •An indirect prompt injection vulnerability in Claude on Chrome can lead to account takeovers.
- •Attackers exploit malicious emails to steal Gmail verification codes via AI interactions.
- •The exploit affects major platforms including Slack, X, and Claude.ai.
Security researchers have identified an indirect prompt injection vulnerability in Claude on Chrome that allows attackers to hijack accounts on platforms like Slack, X, and Claude.ai. The exploit begins when a malicious email is received in the victim's Gmail inbox. When the user asks Claude to summarize recent emails, the AI may inadvertently process the malicious content, leading to the theft of email verification codes. This vulnerability affects users who rely on Claude for email summarization and could result in unauthorized access to multiple accounts. Currently, no specific CVEs have been assigned to this vulnerability, and the researchers have not disclosed any mitigation strategies. The scope of the impact is significant, as it potentially affects all users of the Claude AI tool integrated with Chrome. Users are advised to exercise caution when interacting with emails and using AI tools.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track X in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…