A new vulnerability report reveals that versions of the Claude Chrome extension below 1.0.41 are affected by a high-risk prompt injection flaw. Attackers can exploit this by embedding malicious iframes that load payloads through the a-cdn.claude.ai subdomain, potentially leading to data theft or session hijacking. Users are urged to upgrade to version 1.0.41 or higher. Meanwhile, inflation data from major economies continues to attract market attention.

According to GoPlus, citing a report by Koi, a critical prompt injection vulnerability exists in Anthropic’s Claude Chrome extension, affecting all versions below 1.0.41. Attackers can craft malicious web pages to silently load an iframe containing a cross-site scripting (XSS) vulnerability in the background, executing malicious payloads within the a-cdn.claude.ai subdomain. Since this subdomain is whitelisted as trusted by the extension, attackers can directly inject and automatically execute malicious prompts within the Claude extension without requiring any user authorization or interaction—leaving victims unaware. This vulnerability enables attackers to manipulate the Claude extension to read users’ Google Drive documents, steal business access tokens, export chat histories, and potentially take over the current browser session to perform sensitive actions—such as sending emails—on behalf of the victim. GoPlus recommends users immediately update their Claude extension to version 1.0.41 or higher and remain vigilant against phishing links.