Claude for Chrome flaw could let rogue extensions access your Gmail

2026-07-15T20:51:54Z4b31b2957af4f4a2ae3dcabc770ca708e23f40aa4ae87e82dda4360af49371e8
anthropicassuranceamericablackcatchromechrome-extensionclaudeclaudebleedcrashstealerdata-breachghostcommitgigawipergmailmacosmalwaremicrosoftpatch-tuesdayprompt-injectionransomwarescamssocial-engineeringvulnerabilityzero-day

What happened

Malwarebytes published multiple high-impact reports (July 2026) including a Claude for Chrome flaw (dubbed “ClaudeBleed”) that can let malicious Chrome extensions access Gmail; Microsoft’s July Patch Tuesday fixing 622 Microsoft CVEs (including three zero-days); a macOS credential stealer disguised as Apple’s CrashReporter (CrashStealer) that harvests passwords, browser data and crypto wallets; social-engineering FaceTime scams draining bank accounts; an insider-assisted BlackCat ransomware extortion scheme; a proof‑of‑concept “Ghostcommit” attack that hides prompt-injection payloads inside PN

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
4b31b2957af4f4a2ae3dcabc770ca708e23f40aa4ae87e82dda4360af49371e8
Enrichment time
2026-07-15T20:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Claude for Chrome flaw could let rogue extensions access your Gmail · Baitaphish