Prompt Injection Vulnerabilities in Anthropic's Claude Desktop Extensions
Summary
Hide ▲
Show ▼
Three of Anthropic’s official extensions for Claude Desktop were vulnerable to prompt injection. The affected extensions are the Chrome, iMessage, and Apple Notes connectors. These extensions run unsandboxed with full system permissions, allowing for potential remote code execution (RCE) if exploited. The vulnerabilities were reported through Anthropic's HackerOne program on July 3 and verified as high severity (CVSS 8.9). The issue arises from unsanitized command injection, which could enable malicious actors to execute commands on a user's device. The extensions are packaged as Model Context Protocol (MCP) servers and allow Claude, the underlying large language model (LLM), to act on behalf of the user. The vulnerabilities could lead to the theft of sensitive information, including SSH keys, AWS credentials, and browser passwords.
Timeline
-
05.11.2025 12:30 1 articles · 5d ago
Prompt Injection Vulnerabilities in Anthropic's Claude Desktop Extensions Disclosed
Researchers at Koi Security discovered that three of Anthropic’s official extensions for Claude Desktop were vulnerable to prompt injection. The affected extensions are the Chrome, iMessage, and Apple Notes connectors. These extensions run unsandboxed with full system permissions, allowing for potential remote code execution (RCE) if exploited. The vulnerabilities were reported through Anthropic's HackerOne program on July 3 and verified as high severity (CVSS 8.9). The issue arises from unsanitized command injection, which could enable malicious actors to execute commands on a user's device and steal sensitive information.
Show sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
Information Snippets
-
Three of Anthropic’s official extensions for Claude Desktop were vulnerable to prompt injection.
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
-
The affected extensions are the Chrome, iMessage, and Apple Notes connectors.
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
-
The vulnerabilities were reported through Anthropic's HackerOne program on July 3 and verified as high severity (CVSS 8.9).
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
-
The vulnerabilities arise from unsanitized command injection, allowing for potential remote code execution (RCE).
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
-
The extensions run unsandboxed with full system permissions, enabling access to sensitive information.
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30
-
The extensions are packaged as Model Context Protocol (MCP) servers and allow Claude to act on behalf of the user.
First reported: 05.11.2025 12:301 source, 1 articleShow sources
- Claude Desktop Extensions Vulnerable to Web-Based Prompt Injection — www.infosecurity-magazine.com — 05.11.2025 12:30