Cyber & Technology — 2026-03-27
Zero-Click Claude Chrome Extension Vulnerability Enabled Silent Prompt Injection From Any Website
Security researchers publicly detailed "ShadowPrompt," a zero-click vulnerability in Anthropic's Claude Chrome extension that allowed any website to silently inject prompts into the AI assistant. The flaw chained an overly permissive origin allowlist with a DOM-based XSS vulnerability in an
Analysis
The ShadowPrompt vulnerability class, using AI browser extensions as attack surfaces for prompt injection, will accelerate as AI assistants gain deeper system access. The December-to-March disclosure timeline shows responsible disclosure working, but the broader implication is that every AI tool with browser integration creates an implicit trust boundary that attackers can exploit.
The ShadowPrompt vulnerability class, using AI browser extensions as attack surfaces for prompt injection, will accelerate as AI assistants gain deeper system access. The December-to-March disclosure timeline shows responsible disclosure working, but the broader implication is that every AI tool with browser integration creates an implicit trust boundary that attackers can exploit.