A critical remote code execution (RCE) vulnerability has been identified in three official extensions for Anthropic's Claude Desktop. The vulnerability, which affects Chrome, iMessage, and Apple Notes connectors, results from unsanitized command injection and carries a high CVSS severity score of 8.9.

Published by Anthropic on its extension marketplace, the vulnerabilities could allow attackers to execute arbitrary code on users' computers through seemingly innocent interactions with the AI assistant. Fortunately, Anthropic has patched all three issues.
See also: Critical vulnerabilities in Cisco Unified Contact Center Express
The discovery by KOI Security highlights the risks in emerging AI ecosystems, where extensions connect powerful language models and locale systems with minimal safeguards. Unlike browser add-ons, these tools operate with full system privileges, increasing the potential for damage from basic security flaws.
Claude Desktop Extensions: Vulnerabilities
Claude Desktop extensions operate as packaged MCP servers, distributed as .mcpb bundles, which are essentially zip files containing server code and function manifests. They offer a one-click installation, similar to Chrome extensions, but lack the isolation that protects browser environments. Instead, they run unsandboxed on the host computer, providing access to files, commands, credentials, and system settings . This design positions them as privileged intermediaries between Claude’s AI and the operating system , making them both powerful and dangerous.

The vulnerabilities exploited this trust. Each extension processed user input, such as URLs or messages, via AppleScript commands without proper sanitization. For example, a command to open a URL in Chrome used template literals to directly input the input. This allowed an attacker to create a malicious input that could escape the string context and inject arbitrary AppleScript, triggering shell commands with elevated privileges.
See also: Multiple vulnerabilities in Django allow SQL Injection and DoS
The real danger lies not in users typing malicious commands, but in prompt injection via web content. Claude Desktop regularly retrieves and parses web pages to answer questions, creating an unintended attack vector.
An attacker, controlling a search results page, could detect Claude's user agent and deliver customized malicious content. The AI interprets this as helpful instructions and can trigger the vulnerable Chrome extension, allowing the injected code to silently execute and potentially steal sensitive information such as SSH keys, AWS credentials, and browser passwords . It can also install backdoors without the user knowing.
These vulnerabilities in Anthropic’s extensions raise concerns about the maturity of the MCP ecosystem. As independent developers flood the market with AI-powered (under limited review), the risks associated with full-privilege extensions could escalate. Users should treat these tools as high-risk executables and prioritize updates.
See also: Cisco: Hackers exploit ASA and FTD vulnerability

Anthropic’s quick fixes mitigate immediate threats, but the incident highlights the need for strong security practices across all AI platforms. Ongoing research aims to identify such issues early, protecting users in this rapidly evolving landscape.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
