Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website
Ravie LakshmananMar 26, 2026Browser Security / Vulnerability Cybersecurity researchers have disclosed a vulnerability in Anthropic’s Claude Google Chrome Extension that could have been exploited to trigger malicious prompts simply by visiting a web page. The…







![[Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks [Webinar] Stop Guessing. Learn to Validate Your Defenses Against Real Attacks](https://i1.wp.com/blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgCypzkb6uvHuNx6LKknUqtvQFoqsr6aalztDeBKT1aaUASzfjZMZAZqExx1k0w5iKWl08lx3MxbM_FwWxAvBdZODEerioaMp8OHVvhSjC8VL3uAW9_NMniMl_niggBVhVMdDFu2324YyhW5TrK4fua1PXlrb0DweOULvNgi5mlQUZUct_dIX3OePrfqks/s1600/validate.jpg?w=930&resize=930,620&ssl=1)

