Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Chrome Exploit Steals Gmail Codes to Hijack Accounts

Chrome Exploit Steals Gmail Codes to Hijack Accounts

Posted on August 7, 2026 By CWS

An indirect prompt injection vulnerability within Claude on Chrome has been identified as a vector for stealing email verification codes, allowing hackers to hijack accounts on platforms like Slack, X, and Claude.ai.

Understanding the Exploit

The attack initiates with a deceptive email sent to a target’s Gmail. When the user employs Claude in Chrome to summarize recent emails, the assistant might inadvertently process the attacker’s message.

This email contains hidden commands, enabling Claude to execute JavaScript via its javascript_tool without the user’s knowledge. Previous studies outlined the progression from a browser alert to arbitrary code execution, but recent analysis emphasizes the severe risk of account takeovers via email authentication.

Mechanism of Account Takeover

The core issue lies in the JavaScript tool operating within the authenticated browser session, granting malicious scripts access to signed-in services like Gmail. An attacker can initiate password resets or verification requests for other platforms and monitor the victim’s inbox for these codes.

A critical component of this exploit involves Gmail’s Atom feed endpoint. With the session pre-authenticated, attacker-controlled code can fetch recent email metadata, searching for confirmation codes or magic links for various services.

Impact on Different Platforms

Researchers from Zenity Labs discovered that attackers utilized malicious JavaScript packages from a custom registry mimicking a legitimate CDN. These packages could perform benign actions while secretly engaging in account takeovers.

In Slack’s case, an attacker requests a sign-in code sent to the victim’s email. Through an automated process, the code is extracted from the Gmail Atom feed and sent to the attacker, who completes the login.

The attack on X required deeper analysis due to its complex API steps and browser checks. After triggering a password reset and acquiring the verification code, the attacker could change the password and gain an authenticated session.

Similarly, Claude.ai’s passwordless magic-link process was exploited. The emailed magic link contains a nonce, which can be extracted and used to authenticate with Claude.ai, potentially compromising extensive data and connectors.

Broader Implications

This research underlines the critical threat posed by indirect prompt injection, browser-based code execution, and email as an authentication vector. Any AI browser agent capable of reading untrusted content and executing code in an authenticated session can convert inbox access into a vulnerability for account takeovers.

To mitigate such risks, enhancing security measures around email verification processes and browser session management is vital.

Cyber Security News Tags:account takeover, Chrome vulnerability, Claude.ai security, cybersecurity threat, email phishing, Gmail security, JavaScript exploit, prompt injection, Slack security, X security

Post navigation

Previous Post: Critical Flaws in Gemini CLI and Claude Code Exposed

Related Posts

Want to Validate Alerts Faster? Use Free Threat Intelligence from 15K SOCs Want to Validate Alerts Faster? Use Free Threat Intelligence from 15K SOCs Cyber Security News
JetBrains Resolves Critical IntelliJ and TeamCity Flaws JetBrains Resolves Critical IntelliJ and TeamCity Flaws Cyber Security News
Linux Kernel Bridge Vulnerability Exposes Security Risks Linux Kernel Bridge Vulnerability Exposes Security Risks Cyber Security News
Cybercriminals Exploit Cloud Services for Phishing Cybercriminals Exploit Cloud Services for Phishing Cyber Security News
Critical Vulnerability in Microsoft Edge Poses Security Risk Critical Vulnerability in Microsoft Edge Poses Security Risk Cyber Security News
BlueNoroff Targets Cryptocurrency Through Fake Zoom Meetings BlueNoroff Targets Cryptocurrency Through Fake Zoom Meetings Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Chrome Exploit Steals Gmail Codes to Hijack Accounts
  • Critical Flaws in Gemini CLI and Claude Code Exposed
  • Swiss Government SharePoint Servers Hacked, 200 Accounts Affected
  • Malware Exploits Windows Hello Keys for Entra ID Access
  • Chrome 151 Update Addresses Critical Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark