Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it?

So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it?

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
9 Indlæg 9 Posters 11 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchangeM This user is from outside of this forum
    mttaggart@infosec.exchange
    wrote sidst redigeret af
    #1

    So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

    Yeah, don't let this one in.

    https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

    matildalove@wetdry.worldM tante@tldr.nettime.orgT kroppeb@tech.lgbtK tonyangelo@mspsocial.netT dckim@mastodon.socialD 8 Replies Last reply
    1
    0
    • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

      So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

      Yeah, don't let this one in.

      https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

      matildalove@wetdry.worldM This user is from outside of this forum
      matildalove@wetdry.worldM This user is from outside of this forum
      matildalove@wetdry.world
      wrote sidst redigeret af
      #2

      @mttaggart wow it's so weird how when you increase "productivity" manyfold without paying actual humans to take the time to make it happen, you get all these explosive issues and vulnerabilities

      1 Reply Last reply
      0
      • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

        So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

        Yeah, don't let this one in.

        https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

        tante@tldr.nettime.orgT This user is from outside of this forum
        tante@tldr.nettime.orgT This user is from outside of this forum
        tante@tldr.nettime.org
        wrote sidst redigeret af
        #3

        @mttaggart The "s" in Anthropic stands for security

        1 Reply Last reply
        0
        • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

          So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

          Yeah, don't let this one in.

          https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

          kroppeb@tech.lgbtK This user is from outside of this forum
          kroppeb@tech.lgbtK This user is from outside of this forum
          kroppeb@tech.lgbt
          wrote sidst redigeret af
          #4

          @mttaggart ugh, why do they have to have ai generated blog posts.

          1 Reply Last reply
          0
          • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

            So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

            Yeah, don't let this one in.

            https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

            tonyangelo@mspsocial.netT This user is from outside of this forum
            tonyangelo@mspsocial.netT This user is from outside of this forum
            tonyangelo@mspsocial.net
            wrote sidst redigeret af
            #5

            @mttaggart this is why Anthropic needs to make Mythos available, so companies like Anthropic can catch these bugs!

            1 Reply Last reply
            0
            • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

              So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

              Yeah, don't let this one in.

              https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

              dckim@mastodon.socialD This user is from outside of this forum
              dckim@mastodon.socialD This user is from outside of this forum
              dckim@mastodon.social
              wrote sidst redigeret af
              #6

              @mttaggart VANILLA is good. No external dependencies should be pressed a little bit harder. And... it would be great to have that packaged in a single file. Try telling these 'Claudes' to do it that way.

              1 Reply Last reply
              0
              • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

                Yeah, don't let this one in.

                https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

                lapt0r@infosec.exchangeL This user is from outside of this forum
                lapt0r@infosec.exchangeL This user is from outside of this forum
                lapt0r@infosec.exchange
                wrote sidst redigeret af
                #7

                @mttaggart browser extension development and security practices writ large are stuck in 1995 I stg

                1 Reply Last reply
                0
                • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                  So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

                  Yeah, don't let this one in.

                  https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.townD This user is from outside of this forum
                  drwho@masto.hackers.town
                  wrote sidst redigeret af
                  #8

                  @mttaggart Working as intended.

                  1 Reply Last reply
                  0
                  • mttaggart@infosec.exchangeM mttaggart@infosec.exchange

                    So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

                    Yeah, don't let this one in.

                    https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/

                    float13@masto.hackers.townF This user is from outside of this forum
                    float13@masto.hackers.townF This user is from outside of this forum
                    float13@masto.hackers.town
                    wrote sidst redigeret af
                    #9

                    @mttaggart

                    2001: I'm afraid I can't do that...

                    2026: I'm afraid I *can* do that!

                    "AI"... Service with a smile!

                    1 Reply Last reply
                    0
                    • pelle@veganism.socialP pelle@veganism.social shared this topic
                    Svar
                    • Svar som emne
                    Login for at svare
                    • Ældste til nyeste
                    • Nyeste til ældste
                    • Most Votes


                    • Log ind

                    • Har du ikke en konto? Tilmeld

                    • Login or register to search.
                    Powered by NodeBB Contributors
                    Graciously hosted by data.coop
                    • First post
                      Last post
                    0
                    • Hjem
                    • Seneste
                    • Etiketter
                    • Populære
                    • Verden
                    • Bruger
                    • Grupper