An indirect prompt-injection vulnerability in Claude within a Chrome browser can be linked to account takeovers affecting Slack, X, and Claude.ai This article explores vulnerability claude chrome. . Researchers Raul Klugman-Onitza and João Donato demonstrated that a single weaponized email serves as the initial access point.
If a user asks Claude to summarize recent messages, hidden prompt-injection elements within an attacker-controlled email may attempt to coerce the assistant into loading a malicious JavaScript package. Zenity's proof-of-concept script monitored Gmail's Atom feed for unread authentication messages like password-reset codes, one-time login codes, and magic links. The password reset process for X involves multiple stages of onboarding and uses guest tokens, anti-automation controls, and JavaScript-based instrumentation to evaluate browser behavior.
Zenity identified a method to automate the required transitions during the reset sequence while waiting for a verification code sent to the victim's Gmail inbox. The Claude.ai demonstration is particularly concerning because it targets the same platform used to initiate the attack, highlighting the need for enhanced security measures on all platforms that use similar methods. A compromised Claude.ai account could expose more than just chat history; it might also provide unauthorized access to authorized connectors, uploaded documents, Gmail, Google Drive, Slack, calendars, and GitHub resources.
Strengthen your Security Operations Center (SOC) and minimize Mean Time To Repair (MTTR) through comprehensive phishing detection and investigation capabilities.












