CyberHappenings logo

Track cybersecurity events as they unfold. Sourced timelines. Filter, sort, and browse. Fast, privacy‑respecting. No invasive ads, no tracking.

Critical Zero-Click RCE Flaw in Claude Desktop Extensions

First reported
Last updated
1 unique sources, 1 articles

Summary

Hide ▲

A critical zero-click remote code execution (RCE) vulnerability in Claude Desktop Extensions (DXT) allows attackers to compromise systems via malicious Google Calendar events. The flaw, rated CVSS 10.0, affects over 10,000 users. Anthropic, the developer, declined to fix it, stating it falls outside their threat model. The vulnerability arises from the lack of security boundaries in the Model Context Protocol (MCP) used by Claude DXT, which executes with full system privileges.

Timeline

  1. 09.02.2026 19:30 1 articles · 5h ago

    Zero-Click RCE Flaw in Claude Desktop Extensions Disclosed

    On February 9, 2026, security researchers at LayerX disclosed a critical zero-click remote code execution flaw in Claude Desktop Extensions (DXT). The vulnerability, rated CVSS 10.0, allows attackers to compromise systems via malicious Google Calendar events. Anthropic, the developer, declined to fix the flaw, stating it falls outside their threat model.

    Show sources

Information Snippets