Claude for Chrome: a spoofed click from an extension may expose Gmail and Calendar

Colleagues, I’d like to flag a cybersecurity issue.
I’ve noticed a flaw in Claude for Chrome: another extension with access to claude.ai can spoof a click and trigger tasks for Gmail, Google Docs, and Calendar.
In “ask before acting” mode, the confirmation prompt remains. But if “Act without asking” is enabled, the action may run without any prompt.
No patch is available yet. I would disable automation now and review all extensions that can read or modify data on claude.ai.
Why this matters: it sits at the boundary between convenient automation and unauthorized access to work data.
Are you already reviewing browser extension permissions?
#cybersecurity #browsersecurity #AIsecurity #vulnerability

