Vulnerability in Claude Extension for Chrome Exposes AI Agent to Takeover
2026-05-08T07:24:07Z•4cf989a3e65320e609b80baede93d39dadba2332a107e8f271b389aa4ab41ce6
CVE-2026-6973adversarial-examplesai-coding-agentschrome-148chrome-extensionclaudedaemon-toolsepmminteger-overflowivantimcp-hijackingoauthpalo-alto-zero-dayprompt-injectionstate-sponsoredsupply-chaintrustfalluse-after-freevision-language-modelsvulnerability
What happened
Multiple high-risk security stories: a flaw in the Claude Chrome extension can allow prompt-injection and AI-agent takeover; Mitiga researchers disclosed MCP hijacking that can intercept Claude Code OAuth tokens and maintain persistent SaaS access; Ivanti patched an exploited EPMM zero-day (CVE-2026-6973) that allows arbitrary code execution with admin privileges; Chrome 148 and other updates address critical integer-overflow and use-after-free bugs; a Palo Alto zero-day was exploited in a campaign with indicators of Chinese state activity; Cisco researchers demonstrated imperceptible-image (V
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 4cf989a3e65320e609b80baede93d39dadba2332a107e8f271b389aa4ab41ce6
- Enrichment time
- 2026-05-08T07:24:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.