A reported flaw in the Claude Chrome extension highlights a hard truth: in browser agents, the danger is often not a broken model, but a broken trust boundary.
A fake TronLink extension targeting TRON users shows how browser trust, not just malware code, has become the real battleground for crypto theft.
A reported flaw in Anthropic’s Claude in Chrome puts a sharper spotlight on the weakest part of agentic browsing: the chain of permissions that links a browser add-on to Gmail, Drive, and code repositories.
Researchers uncover a critical flaw in the Claude Chrome extension, exposing users’ private data to stealthy cyberattacks.
A critical flaw in Anthropic’s Claude Chrome extension lets attackers seize control of the AI assistant, risking widespread data theft and user impersonation.
A fake ChatGPT ad blocker secretly spied on users and siphoned private chats to hackers, raising new alarms over Chrome Web Store security.
A zero-click vulnerability let attackers hijack the Claude AI Chrome extension, turning innocent browsing into a covert cyberattack.
A popular Chrome add-on secretly funneled user purchases to cybercriminals for weeks before Google intervened.
A sophisticated Chrome extension scam preys on cryptocurrency users by mimicking a trusted wallet brand and harvesting their most sensitive secrets.
A popular visual search tool is hijacked, exposing thousands to invisible browser attacks that bypass security at every turn.
A popular Chrome extension was hijacked to launch sophisticated attacks, draining crypto wallets and manipulating browser security.
A bogus Chrome extension promises convenience but steals the keys to the Meta Business kingdom.
A seemingly harmless VK customization tool was weaponized to hijack accounts, spread malware, and monetize victims—right under Chrome’s nose.
A deceptive Chrome extension impersonates a popular ad blocker, weaponizing browser crashes to infiltrate enterprise networks with advanced malware.
A look inside the CrashFix campaign, where a rogue Chrome extension brings browser crashes, fake security pop-ups, and a stealthy RAT to corporate networks.
A rogue browser extension masquerades as a trading tool while secretly siphoning off powerful credentials from unsuspecting crypto users.
A malicious Chrome extension exploits cryptocurrency traders worldwide, stealing API credentials and draining wallets under the guise of automation.
New research reveals how Anthropic’s AI-powered Chrome tool could expose private data—and open the door to novel cyberattacks.