Claude for Chrome flaw could let rogue extensions access your Gmail
2026-07-15T20:51:54Z•4b31b2957af4f4a2ae3dcabc770ca708e23f40aa4ae87e82dda4360af49371e8
anthropicassuranceamericablackcatchromechrome-extensionclaudeclaudebleedcrashstealerdata-breachghostcommitgigawipergmailmacosmalwaremicrosoftpatch-tuesdayprompt-injectionransomwarescamssocial-engineeringvulnerabilityzero-day
What happened
Malwarebytes published multiple high-impact reports (July 2026) including a Claude for Chrome flaw (dubbed “ClaudeBleed”) that can let malicious Chrome extensions access Gmail; Microsoft’s July Patch Tuesday fixing 622 Microsoft CVEs (including three zero-days); a macOS credential stealer disguised as Apple’s CrashReporter (CrashStealer) that harvests passwords, browser data and crypto wallets; social-engineering FaceTime scams draining bank accounts; an insider-assisted BlackCat ransomware extortion scheme; a proof‑of‑concept “Ghostcommit” attack that hides prompt-injection payloads inside PN
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- 4b31b2957af4f4a2ae3dcabc770ca708e23f40aa4ae87e82dda4360af49371e8
- Enrichment time
- 2026-07-15T20:51:54Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.