HomeSecurityAnthropic's DXT has a "critical RCE vulnerability"

Anthropic's DXT has a "critical RCE vulnerability"

When LayerX Security published a report on Monday describing what it called “a critical click-through RCE vulnerability in Anthropic’s Claude Desktop Extensions (DXT) that allows a malicious Google Calendar invitation to silently compromise an entire system,” analysts, consultants, security leaders, and even Anthropic didn’t dispute the facts. However, the revelation reignited the debate over whether it’s the responsibility of AI vendors to provide secure products or whether it’s the responsibility of CISOs to change settings to suit their business environment.

See also: BeyondTrust patches critical RCE vulnerability in Remote Support and PRA

DXT

"Unlike traditional browser extensions, Claude Desktop Extensions operate unsandboxed with full system privileges. As a result, Claude can autonomously connect low-risk links, such as Google Calendar, to high-risk local executors without the user's awareness or consent," the report says.

Roy Ben Alta, CEO of AI company Oakie.ai and former director of AI for Meta, said the issue is real, but that it's more about how Anthropic designed its systems and its choice to operate as a browser and desktop extension.

He noted that the issue is not unique to Anthropic. Any AI agent with access to external data and local execution capabilities offers potential avenues for privilege escalation. Steven Eric Fisher , an independent cybersecurity and risk consultant who served as Walmart’s director of cybersecurity, risk and compliance until August 2025, agreed that the problem stems from how Anthropic DXT was designed to work, as opposed to a technical flaw.

Researchers at LayerX Security stated that, while it is true that these licensing/configuration issues exist to varying degrees with all AI vendors, Anthropic's approach with DXT makes the security problem much worse.

Roy Paz , principal AI security researcher at LayerX Security, said he tested DXT against Perplexity 's Comet , OpenAI 's Atlas , and Microsoft 's CoPilot , and the differences were stark. " When you ask Copilot, Atlas, or Perplexity to use a tool, they'll use that tool for you. But Claude DXT allows tools to talk to other tools, like Google Calendar with Desktop Commander, and it can do so without consulting the user to complete a task ," Paz said.

See also: SmarterMail fixes critical RCE vulnerability

Anthropic's DXT has a "critical RCE vulnerability"

With these other vendors, he noted, "if the agent wants to do something that goes beyond the scope of the user's explicit instruction, it will ask for permission, but with Claude DXT, the user is not notified."

Anthropic spokesperson Jennifer Martinezstates: “To be clear, the situation described in the post requires a targeted user to have intentionally installed these tools and granted permission to run them without prompting. We recommend that users exercise the same caution when installing MCP servers as they do when installing [other] third-party software.”

Martinez added that users explicitly configure and grant permissions to MCP servers they choose to run locally, and those servers access resources based on the user's permissions.

However, Frank Dickson, group vice president for security and trust at IDC, refuted the suggestion that this is a problem common to all autonomous agents. "This bug is more about reinforcing the need to secure and control the browser than Anthropic releasing an insecure browser."

LayerX's Paz said this problem won't be easy for Anthropic to fix, because it's deeply embedded in architectural decisions. "It's not a half-hour fix. It's weeks of work. It's going to force them to do a complete redesign."

See also: SolarWinds: Critical RCE vulnerabilities in Web Help Desk

Anthropic's DXT has a "critical RCE vulnerability"

Rock Lambros, CEO of security firm RockCyber, added that he wouldn't consider the Anthropic issue a zero day, but it's still a problem. "Every company deploying agents right now has to answer the question, 'Did we restrict tool connection privileges before activation, or did we give the key to the intern and go to lunch?'"

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS