The ClaudeBleed vulnerability still lets malicious Chrome extensions abuse Claude for Chrome's permissions.

A ClaudeBleed-linked vulnerability in Claude for Chrome remains unpatched, allowing other extensions to access data.

Claude for Chrome v1.0.80 still accepts forged clicks from other extensions, triggering Gmail, Docs, and Calendar tasks silently in hands-off mode.