Researchers at LayerX disclosed on May 14, 2026 a vulnerability in Anthropic’s Claude Chrome extension that let any browser plugin, even one without special permissions, inject malicious prompts and hijack the AI agent’s session. The flaw could let an attacker access sensitive data across connected apps such as Google Drive, GitHub repositories, and email within a user’s trusted session, extract files and credentials, and delete evidence of the unauthorized actions to cover their tracks. No confirmed real-world exploitation was reported at disclosure.