SECURITY·중요도 8·2026. 07. 14.·The Hacker News
Researchers Say Claude for Chrome Flaw Lets Rogue Extensions Trigger Gmail Reads
── KO ──────────────────
론트의 Chrome 취약점으로 악성 확장이 Gmail 접근 가능해져.
연구자들은 Claude for Chrome의 취약점을 발견하였으며, 이로 인해 악성 브라우저 확장이 Gmail, Google Docs 및 Calendar에 접근할 수 있다고 경고하고 있다. 이 취약점은 사용자 컴퓨터에서 이미 실행 중인 스크립트를 통해 발생하며, Anthropic은 이 문제를 해결하기 위해 임의 프롬프트 접근을 제한한 바 있다. 이는 ClaudeBleed와 유사하지만, 더 넓은 범위를 가지고 있다.
── EN ──────────────────
Vulnerability in Claude for Chrome allows rogue extensions to access Gmail.
Researchers have discovered a vulnerability in Claude for Chrome that enables malicious browser extensions to access Gmail, Google Docs, and Calendar. This flaw requires a rogue extension that can run a script on claude.ai. Anthropic has attempted to mitigate this issue by restricting arbitrary-prompt access, similar to the ClaudeBleed vulnerability, but with a broader scope.