Security researchers have disclosed two vulnerabilities in Anthropic’s Claude for Chrome browser extension that pose particular risks to Mac users, who commonly use Chrome as their primary browser alongside Apple’s native tools.
The flaws, discovered by Manifold Security, allow any other browser extension with access to the claude.ai domain to forge clicks that trigger Claude to read Gmail messages, Google Docs, and Calendar data. The vulnerability affects Claude for Chrome v1.0.80 and earlier on macOS.
Mac users who enabled Claude’s “Act without asking” automation mode face the highest risk. In that configuration, a rogue extension can silently read Gmail and Docs content without any user interaction. Even in “ask before acting” mode, a user may be tricked into approving a forged task.
The first flaw involves a content script that fails to check the event.isTrusted browser flag, accepting synthetic clicks as genuine. A second issue involves a skipPermissions parameter that could bypass the approval step entirely.
Mac users should immediately disable “Act without asking” mode and review which extensions have permission to read or change data on claude.ai. Anthropic has not yet shipped a patch as of July 14. The vulnerabilities highlight the expanding attack surface created by AI browser extensions accessing sensitive user data on macOS.