Mastodon Feed: Post

Mastodon Feed

Boosted by glyph ("Glyph"):
mttaggart@infosec.exchange ("Taggart :ifin:") wrote:

So the Claude extension allows any other extension to inject JavaScript into claude.ai and run it? Cool cool cool.

Yeah, don't let this one in.

https://layerxsecurity.com/blog/a-flaw-in-claudes-browser-extension-allows-any-extension-to-hijack-it/