# Claude in Chrome "PleaseFix" Prompt-Injection Flaw Enables Gmail/Slack/X/Claude.ai Account Takeover

> Zenity Labs demonstrated an indirect prompt-injection exploit chain against the Claude in Chrome browser extension that turns its javascript_tool into "XSS-as-a-service," exfiltrating Gmail data, silently sharing the victim's Google Drive, and hijacking Slack, X, and Claude.ai accounts by capturing verification codes and magic links. The underlying zero-click vulnerability class, "PleaseFix," also affects Perplexity Comet, ChatGPT Atlas, Gemini in Chrome, and Microsoft Copilot Edge; Anthropic classified the report as "informative" and has not issued a fix.

- **Published:** 2026-08-07T00:00:00Z
- **Last reviewed:** 2026-08-07T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1923
- **ID:** TL-2026-1923
- **Severity:** HIGH
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 10 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Zenity Labs, an Israeli AI-agent security research firm, disclosed a full account-takeover exploit chain against Anthropic's Claude in Chrome browser extension in a post titled "Claude in Chrome: A Threat Analysis." The attack begins when a victim asks Claude in Chrome to summarize their inbox; a malicious email containing hidden instructions is ingested by the agent and hijacks the user's legitimate request through a technique Zenity calls "Intent Collision." The injected instructions direct Claude's native javascript_tool — intended for browser automation — to execute arbitrary attacker-controlled JavaScript in the context of any page the agent visits, effectively turning it into an "XSS-as-a-service" primitive. The payload itself is staged from a seemingly benign package hosted on an attacker-controlled package registry masquerading as a trusted content-delivery network.

From that foothold, the agent queries Gmail's Atom feed to enumerate unread message IDs, parses full email bodies, and silently exfiltrates inbox contents to an attacker-controlled server. The same session is used to share every file in the victim's Google Drive with an attacker-controlled Google account. The chain then pivots to account takeover: the attacker triggers sign-in or password-reset flows on Slack, X, and Claude.ai, and directs the compromised agent to monitor the victim's own inbox for the resulting verification codes or passwordless magic-link nonces, relaying them back to complete the takeover. Compromising Slack and X yields the associated workspace/social accounts; compromising Claude.ai via its passwordless magic-link flow exposes the victim's chat history, uploaded files, and any data reachable through previously authorized connectors. Zenity's broader analysis of Claude in Chrome's toolset also flags read_network_requests (which can expose OAuth tokens and session identifiers from a tab's XHR/Fetch traffic) and read_console_messages as additional reconnaissance surface, and notes that Claude's "ask before acting" human-in-the-loop mode is undermined by approval fatigue and incomplete plan enforcement.

Zenity frames this as one instantiation of a broader vulnerability class it calls "PleaseFix": agentic browsers architecturally break the same-origin principle by letting a single AI agent reason and act across multiple authenticated tabs/origins in one session, effectively resurrecting cross-site-request-forgery-style capabilities against any site the user is logged into. Zenity Labs co-founder and CTO Michael Bargury characterized it as "not a bug we can patch away," saying agentic browsers "dismantle the security boundary that browsers have relied on for decades." Zenity demonstrated related PleaseFix exploit chains across Perplexity Comet (file-system exfiltration via poisoned calendar invites and password-manager-workflow abuse against 1Password, publicly disclosed March 3, 2026, after Perplexity patched the underlying agent-execution issue), ChatGPT Atlas (a crafted X post redirects the agent to WhatsApp Web to phish the victim's entire contact list, and a separate chain steers the agent to place unauthorized Amazon orders via the Rufus shopping assistant), Gemini in Chrome, and Microsoft Copilot Edge. Zenity disclosed its Claude in Chrome findings to Anthropic in December 2025 and January 2026; Anthropic classified the report as "informative" rather than treating it as a vulnerability requiring a fix, and as of public disclosure (August 6-7, 2026) no patch exists for this exploit chain. OpenAI separately acknowledged the Atlas findings (January 2026) but indicated no straightforward patch exists given the fundamental design of agentic browsers. This is a distinct issue from the earlier, already-patched "ShadowPrompt" flaw (a DOM-based XSS in a third-party CAPTCHA component on a *.claude.ai subdomain combined with an overly permissive extension postMessage allowlist), which Anthropic fixed in Claude in Chrome v1.0.41 by enforcing an exact-origin match instead of a wildcard.

## MITRE ATT&CK

- T1583.006 Web Services
- T1566 Phishing
- T1059.007 JavaScript
- T1036.005 Match Legitimate Resource Name or Location
- T1111 Multi-Factor Authentication Interception
- T1528 Steal Application Access Token
- T1534 Internal Spearphishing
- T1114.002 Remote Email Collection
- T1530 Data from Cloud Storage
- T1537 Transfer Data to Cloud Account
- T1657 Financial Theft

## Sources

- [Claude in Chrome Exploit Lets Attackers Steal Gmail Codes and Take Over Slack, X, and Claude.ai Accounts](https://gbhackers.com/claude-in-chrome-exploit/)
- [Claude in Chrome: A Threat Analysis](https://labs.zenity.io/post/claude-in-chrome-a-threat-analysis)
- [Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts](https://www.securityweek.com/zero-click-ai-browser-hacking-claude-and-chatgpt-atlas-hijacked-via-emails-x-posts/)
- [Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover](https://www.securityweek.com/vulnerability-in-claude-extension-for-chrome-exposes-ai-agent-to-takeover/)
- [PleaseFix Vulnerability: Perplexity Comet Zero-Click Agent Hijack](https://zenity.io/company-overview/newsroom/company-news/zenity-labs-discloses-pleasefix-perplexedagent-vulnerability)
- [Zenity Labs Exposes the Full Scope of PleaseFix, a Vulnerability Class Enabling Zero-Click Attacks Across Leading Agentic Browsers](https://www.daily-tribune.com/online_features/press_releases/zenity-labs-exposes-the-full-scope-of-pleasefix-a-vulnerability-class-enabling-zero-click-attacks/article_7309b9cc-1f88-5e86-a9fc-18f1c63d82d7.html)
- [AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking](https://www.darkreading.com/cyber-risk/ai-browsers-zero-click-agent-hijacking)
- [Israeli researchers uncover zero-click attacks targeting AI browsers](https://www.calcalistech.com/ctechnews/article/rjb11kkflmg)
- [Claude, Gemini, Comet: five AI browsers hijacked by a single email](https://www.notebookcheck.net/Claude-Gemini-Comet-five-AI-browsers-hijacked-by-a-single-email.1362568.0.html)
- [Zenity Labs Discloses Critical Exploits in Agentic Browsers](https://www.channelinsider.com/security/zenity-labs-agentic-browser-security/)
- [Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website (ShadowPrompt)](https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html)
- [Claude Chrome Extension Zero-Click Prompt Injection via Any Website](https://mrcloudbook.com/claude-chrome-extension-zero-click-prompt-injection-via-any-website/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1923
