Claude Desktop Extension Can Be Hijacked to Deliver Malware Using a Simple Google Calendar Event



  • LayerX warns that Claude desktop extensions allow quick no-click injection attacks
  • Extensions run without a sandbox and with full system privileges, putting remote code execution at risk
  • Bug rated CVSS 10/10, seems unresolved

Claude Desktop Extensions, due to their very nature, can be exploited for fast, zero-click injection attacks that can lead to remote code execution (RCE) and compromise the entire system, experts warned.

Claude is Anthropic’s AI assistant and one of the most popular GenerativeAI models out there. It offers desktop extensions: MCP servers packaged and distributed through the Anthropic extensions marketplace, which when installed appear similar to Chrome add-ons.



Leave a Comment

Your email address will not be published. Required fields are marked *