<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it?]]></title><description><![CDATA[<p>So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.</p><p>Yeah, don't let this one in.</p><p><a href="https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/" rel="nofollow noopener"><span>https://</span><span>layerxsecurity.com/blog/a-flaw</span><span>-in-claudes-browser-extension-allows-any-extension-to-hijack-it/</span></a></p>]]></description><link>https://forum.fedi.dk/topic/f713341d-479e-42e5-8fd5-9861be227906/so-the-claude-extension-allows-any-other-extension-to-inject-javascript-into-claude.ai-and-run-it</link><generator>RSS for Node</generator><lastBuildDate>Thu, 14 May 2026 03:41:01 GMT</lastBuildDate><atom:link href="https://forum.fedi.dk/topic/f713341d-479e-42e5-8fd5-9861be227906.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 08 May 2026 13:22:02 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 16:39:15 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> </p><p>2001: I'm afraid I can't do that...</p><p>2026: I'm afraid I *can* do that!</p><p>"AI"... Service with a smile! <img class="not-responsive emoji" src="https://cdn.masto.host/mastohackerstown/custom_emojis/images/000/004/450/original/0b5081884e858968.png" title=":facepalm:" /> <img class="not-responsive emoji" src="https://cdn.masto.host/mastohackerstown/custom_emojis/images/000/004/450/original/0b5081884e858968.png" title=":facepalm:" /> <img class="not-responsive emoji" src="https://cdn.masto.host/mastohackerstown/custom_emojis/images/000/004/450/original/0b5081884e858968.png" title=":facepalm:" /></p>]]></description><link>https://forum.fedi.dk/post/https://masto.hackers.town/users/float13/statuses/116539939581177322</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://masto.hackers.town/users/float13/statuses/116539939581177322</guid><dc:creator><![CDATA[float13@masto.hackers.town]]></dc:creator><pubDate>Fri, 08 May 2026 16:39:15 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 16:36:51 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> Working as intended.</p>]]></description><link>https://forum.fedi.dk/post/https://masto.hackers.town/users/drwho/statuses/116539930124053650</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://masto.hackers.town/users/drwho/statuses/116539930124053650</guid><dc:creator><![CDATA[drwho@masto.hackers.town]]></dc:creator><pubDate>Fri, 08 May 2026 16:36:51 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 16:03:37 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> browser extension development and security practices writ large are stuck in 1995 I stg</p>]]></description><link>https://forum.fedi.dk/post/https://infosec.exchange/users/lapt0r/statuses/116539799477796006</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://infosec.exchange/users/lapt0r/statuses/116539799477796006</guid><dc:creator><![CDATA[lapt0r@infosec.exchange]]></dc:creator><pubDate>Fri, 08 May 2026 16:03:37 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 15:56:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> VANILLA is good. No external dependencies should be pressed a little bit harder. And... it would be great to have that packaged in a single file. Try telling these 'Claudes' to do it that way.</p>]]></description><link>https://forum.fedi.dk/post/https://mastodon.social/users/dckim/statuses/116539773387374294</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mastodon.social/users/dckim/statuses/116539773387374294</guid><dc:creator><![CDATA[dckim@mastodon.social]]></dc:creator><pubDate>Fri, 08 May 2026 15:56:59 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 15:13:50 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> this is why Anthropic needs to make Mythos available, so companies like Anthropic can catch these bugs!</p>]]></description><link>https://forum.fedi.dk/post/https://mspsocial.net/users/tonyangelo/statuses/116539603724181198</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://mspsocial.net/users/tonyangelo/statuses/116539603724181198</guid><dc:creator><![CDATA[tonyangelo@mspsocial.net]]></dc:creator><pubDate>Fri, 08 May 2026 15:13:50 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 15:07:08 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> ugh, why do they have to have ai generated blog posts.</p>]]></description><link>https://forum.fedi.dk/post/https://tech.lgbt/users/Kroppeb/statuses/116539577386879922</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://tech.lgbt/users/Kroppeb/statuses/116539577386879922</guid><dc:creator><![CDATA[kroppeb@tech.lgbt]]></dc:creator><pubDate>Fri, 08 May 2026 15:07:08 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 14:57:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange">@<span>mttaggart</span></a></span> The "s" in Anthropic stands for security</p>]]></description><link>https://forum.fedi.dk/post/https://tldr.nettime.org/users/tante/statuses/116539539262381084</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://tldr.nettime.org/users/tante/statuses/116539539262381084</guid><dc:creator><![CDATA[tante@tldr.nettime.org]]></dc:creator><pubDate>Fri, 08 May 2026 14:57:27 GMT</pubDate></item><item><title><![CDATA[Reply to So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? on Fri, 08 May 2026 13:25:59 GMT]]></title><description><![CDATA[<p><span><a href="/user/mttaggart%40infosec.exchange" rel="nofollow noopener">@<span>mttaggart</span></a></span> wow it's so weird how when you increase "productivity" manyfold without paying actual humans to take the time to make it happen, you get all these explosive issues and vulnerabilities</p>]]></description><link>https://forum.fedi.dk/post/https://wetdry.world/users/matildalove/statuses/116539179624014010</link><guid isPermaLink="true">https://forum.fedi.dk/post/https://wetdry.world/users/matildalove/statuses/116539179624014010</guid><dc:creator><![CDATA[matildalove@wetdry.world]]></dc:creator><pubDate>Fri, 08 May 2026 13:25:59 GMT</pubDate></item></channel></rss>