{"id":12391,"date":"2026-04-25T10:04:59","date_gmt":"2026-04-25T10:04:59","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/claude-desktop-reportedly-adds-browser-access-bridge-to-multiple-chromium-based-browsers\/"},"modified":"2026-04-25T10:04:59","modified_gmt":"2026-04-25T10:04:59","slug":"claude-desktop-reportedly-adds-browser-access-bridge-to-multiple-chromium-based-browsers","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/25\/claude-desktop-reportedly-adds-browser-access-bridge-to-multiple-chromium-based-browsers\/","title":{"rendered":"Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers"},"content":{"rendered":"<p>    Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic\u2019s <a href=\"https:\/\/cybersecuritynews.com\/macos-stealer-miolab\/\" target=\"_blank\" rel=\"noreferrer noopener\">Claude Desktop application for macOS<\/a> silently installs a Native Messaging bridge into the directories of several Chromium-based browsers.<\/p>\n<p>This undocumented behavior occurs without user consent, raising significant privacy and security concerns within the cybersecurity community.<\/p>\n<p>When a user installs Claude Desktop (Claude.app), the application automatically places a Native Messaging manifest file named\u00a0com.anthropic.claude_browser_extension.json into the application support folders of up to seven Chromium-based browsers, including Chrome, Brave, Edge, Arc, Vivaldi, and Opera.<\/p>\n<p>For a browser extension to communicate with a local desktop application, it requires a Native Messaging host. This bridge operates outside the browser\u2019s secure sandbox, running with the same privileges as the user.<\/p>\n<p>The manifest file preauthorizes three specific Chrome extension IDs to trigger the helper binary (chrome-native-host) located in the Claude Desktop app bundle.<\/p>\n<p>Alarmingly, this installation happens automatically even if the user has never installed the <a href=\"https:\/\/cybersecuritynews.com\/claude-chrome-extension-0-click-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Claude browser extension,<\/a> and even in directories for browsers that are not currently installed on the machine.<\/p>\n<p>Furthermore, Claude Desktop rewrites these manifest files whenever it launches, making them difficult to remove permanently.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-security-and-privacy-implications\"><strong>Security and Privacy Implications<\/strong><\/h2>\n<p>While the helper binary remains dormant until activated by one of the three pre-authorized extensions, its presence expands the user\u2019s machine\u2019s attack surface.<\/p>\n<p>If an attacker successfully compromises one of the allowed extension IDs via an account takeover, a <a href=\"https:\/\/cybersecuritynews.com\/131-malicious-extensions-targeting-whatsapp\/\" target=\"_blank\" rel=\"noreferrer noopener\">malicious Web Store update<\/a>, or a compromised build pipeline, they could achieve out-of-sandbox code execution.<\/p>\n<p>The privacy risks are equally severe. According to Anthropic\u2019s own documentation, their browser integrations are designed to share login states, read the <a href=\"https:\/\/cybersecuritynews.com\/mshtml-framework-0-day-exploited\/\" target=\"_blank\" rel=\"noreferrer noopener\">Document Object Model (DOM)<\/a>, extract structured data, and fill forms.<\/p>\n<p>This means a fully activated bridge could allow the AI agent to read decrypted private messages, access banking portals, and capture passwords as they are typed.<\/p>\n<p>Furthermore, Anthropic previously disclosed that its Claude for Chrome extension is vulnerable to <a href=\"https:\/\/cybersecuritynews.com\/prompt-injection-via-github-comments\/\" target=\"_blank\" rel=\"noreferrer noopener\">prompt injection attacks<\/a>.<\/p>\n<p>A successful prompt injection against the extension could, in theory, use the pre-installed Native Messaging bridge to execute commands on the host machine.<\/p>\n<p><a href=\"https:\/\/www.thatprivacyguy.com\/blog\/anthropic-spyware\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">The core issue Hanff highlights<\/a> is the total lack of transparency. The software employs a \u201cdark pattern\u201d by forcing an integration across independent software boundaries without prompting the user to opt in.<\/p>\n<p>Hanff noted that this silent deployment of dormant tracking and automation capabilities may be in direct violation of the EU\u2019s ePrivacy Directive and computer misuse regulations, which strictly govern the storage of information on a user\u2019s terminal equipment.<\/p>\n<p>Standard cybersecurity practices dictate that such powerful system integrations should be installed only when a user actively requests them, be properly scoped to the targeted browser, and be visible within the application\u2019s settings.<\/p>\n<p>As AI tools increasingly seek agentic control over our digital environments, enforcing strict user consent and transparent security boundaries remains critical.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/claude-desktop-reportedly-adds-browser-access\/\">Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/claude-desktop-reportedly-adds-browser-access\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Claude Desktop Reportedly Adds Browser Access Bridge to Multiple Chromium-Based Browsers A recent technical audit by privacy researcher Alexander Hanff has revealed that Anthropic\u2019s Claude Desktop application for macOS silently installs a Native Messaging bridge into the directories of several Chromium-based browsers. This undocumented behavior occurs without user consent, raising significant privacy and security concerns [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[167,768,129,63],"tags":[130],"class_list":["post-12391","post","type-post","status-publish","format-standard","hentry","category-ai","category-chrome","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12391"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12391"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12391\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12391"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12391"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12391"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}