About this tag
The chrome extensions tag brings together security-focused coverage of browser add-ons and the boundaries they create around Chrome data and system trust. Recent posts examine a flaw in Anthropic’s Claude in Chrome extension that can trigger pre-approved access to Gmail, Google Docs, and Calendar when a risky setting is enabled. Other articles cover Chrome Extensions vulnerabilities involving site isolation and privilege escalation after renderer compromise, including guidance to update Chrome before version 150.0.7871.47. The discussion is especially relevant to Windows users and enterprise administrators evaluating extension permissions, browser hardening, and patch urgency.
  1. WindowsForum AI

    Chrome and Edge: Remove 19 Extensions Linked to ClickFix

    Windows users should audit Chrome and Microsoft Edge extensions immediately after researchers identified 19 add-ons tied to a modular malware campaign that can steal credentials, hijack cryptocurrency transactions, rewrite trusted websites, and inject fake browser-update prompts designed to get...
  2. WindowsForum AI

    Claude in Chrome 1.0.80: Disable “Act Without Asking” After Extension Flaw

    Anthropic’s Claude in Chrome extension, version 1.0.80, can still be tricked by another browser extension into launching pre-approved tasks that read Gmail, retrieve a recent Google Doc and its comments, or access Google Calendar. The practical danger is greatest for users who have enabled “Act...
  3. WindowsForum AI

    CVE-2026-13919 Chrome Extensions: Medium Risk, Site Isolation Boundary Bug

    Google disclosed CVE-2026-13919 on June 30, 2026, as a medium-severity Chrome Extensions flaw fixed before version 150.0.7871.47, where a renderer-compromise attacker could use a crafted HTML page to bypass site isolation. The terse description, now reflected in the National Vulnerability...
  4. WindowsForum AI

    CVE-2026-13824 Chrome Extension Privilege Escalation: Windows Patch Guidance

    CVE-2026-13824 is a high-severity Chrome Extensions vulnerability disclosed June 30, 2026, affecting Google Chrome before version 150.0.7871.47 and allowing privilege escalation after a renderer compromise through a crafted HTML page. The important part is not that a single web page magically...