HomeSecurityCritical RCE Vulnerability in Anthropic's Claude Desktop

Critical RCE Vulnerability in Anthropic's Claude Desktop

A critical remote code execution (RCE) vulnerability has been identified in three official extensions for Anthropic's Claude Desktop. The vulnerability, which affects Chrome, iMessage, and Apple Notes connectors, results from unsanitized command injection and carries a high CVSS severity score of 8.9.

Claude Desktop Anthropic

Published by Anthropic on its extension marketplace, the vulnerabilities could allow attackers to execute arbitrary code on users' computers through seemingly innocent interactions with the AI ​​assistant. Fortunately, Anthropic has patched all three issues.

See also: Critical vulnerabilities in Cisco Unified Contact Center Express

The discovery by KOI Security highlights the risks in emerging AI ecosystems, where extensions connect powerful language models and locale systems with minimal safeguards. Unlike browser add-ons, these tools operate with full system privileges, increasing the potential for damage from basic security flaws.

Claude Desktop Extensions: Vulnerabilities

Claude Desktop extensions operate as packaged MCP servers, distributed as .mcpb bundles, which are essentially zip files containing server code and function manifests. They offer a one-click installation, similar to Chrome extensions, but lack the isolation that protects browser environments. Instead, they run unsandboxed on the host computer, providing access to files, commands, credentials, and system settings . This design positions them as privileged intermediaries between Claude’s AI and the operating system , making them both powerful and dangerous.

Critical RCE Vulnerability in Anthropic's Claude Desktop

The vulnerabilities exploited this trust. Each extension processed user input, such as URLs or messages, via AppleScript commands without proper sanitization. For example, a command to open a URL in Chrome used template literals to directly input the input. This allowed an attacker to create a malicious input that could escape the string context and inject arbitrary AppleScript, triggering shell commands with elevated privileges.

See also: Multiple vulnerabilities in Django allow SQL Injection and DoS

The real danger lies not in users typing malicious commands, but in prompt injection via web content. Claude Desktop regularly retrieves and parses web pages to answer questions, creating an unintended attack vector.

An attacker, controlling a search results page, could detect Claude's user agent and deliver customized malicious content. The AI ​​interprets this as helpful instructions and can trigger the vulnerable Chrome extension, allowing the injected code to silently execute and potentially steal sensitive information such as SSH keys, AWS credentials, and browser passwords . It can also install backdoors without the user knowing.

These vulnerabilities in Anthropic’s extensions raise concerns about the maturity of the MCP ecosystem. As independent developers flood the market with AI-powered (under limited review), the risks associated with full-privilege extensions could escalate. Users should treat these tools as high-risk executables and prioritize updates.

See also: Cisco: Hackers exploit ASA and FTD vulnerability

Critical RCE Vulnerability in Anthropic's Claude Desktop

Anthropic’s quick fixes mitigate immediate threats, but the incident highlights the need for strong security practices across all AI platforms. Ongoing research aims to identify such issues early, protecting users in this rapidly evolving landscape.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS