avatar
The Hacker News
@thehackernews
26.03.2026 20:13
⚠️ A flaw in Claude’s Chrome extension let attackers inject prompts by just visiting a page.

No clicks. A hidden iframe + XSS chain made the extension treat attacker input as real user commands, enabling data theft and actions like sending emails.

�� How the silent prompt injection worked → https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html
👍 11
🤯 6
🔥 2
😁 2
52 9.5K

Обсуждение 0

Обсуждение не доступно в веб-версии. Чтобы написать комментарий, перейдите в приложение Telegram.

Обсудить в Telegram

The Hacker News

162.3K
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Открыть в Telegram