Cyber & Technology — 2026-03-27

Zero-Click Claude Chrome Extension Vulnerability Enabled Silent Prompt Injection From Any Website

Security researchers publicly detailed "ShadowPrompt," a zero-click vulnerability in Anthropic's Claude Chrome extension that allowed any website to silently inject prompts into the AI assistant. The flaw chained an overly permissive origin allowlist with a DOM-based XSS vulnerability in an Arkose Labs CAPTCHA component. Combined with prior "Claudy Day" research by Oasis Security demonstrating how prompt injection could enable covert data exfiltration, the disclosure exposes growing risks as AI assistants gain browser-level access. Anthropic patched the extension (v1.0.41) with strict origin checks following responsible disclosure in December 2025.

Analysis
The ShadowPrompt vulnerability class, using AI browser extensions as attack surfaces for prompt injection, will accelerate as AI assistants gain deeper system access. The December-to-March disclosure timeline shows responsible disclosure working, but the broader implication is that every AI tool with browser integration creates an implicit trust boundary that attackers can exploit.
2 sources
  1. Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website - The Hacker News
  2. Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks - Cyber Security News

View in full brief →

UNCLASSIFIED // OPEN SOURCE