Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
endpoint-software-vulnerabilityidentity-authentication-vulnerabilityprivacy-surveillance-policywidely-deployed-product-advisory

Claude Desktop on macOS Accused of Silently Preauthorizing Browser Access

Updated 2mo agoFirst seen Apr 21, 20264 sources

Anthropic’s Claude Desktop for macOS has been accused of silently installing Native Messaging manifest files that preauthorize its browser extensions to communicate with a local helper binary across multiple Chromium-based browsers, including Chrome, Brave, Edge, Arc, Vivaldi, and Opera. Researcher Alexander Hanff reported that the manifests can be written even for browsers not currently installed, meaning future Chromium-based browsers added to the system could automatically inherit the trust relationship. The manifests reportedly authorize specific extension IDs to access a local executable outside the browser sandbox, creating a persistent browser-to-local bridge without clear user notification or consent.

Security researchers said the behavior expands the host attack surface because a compromised or maliciously updated authorized extension could potentially trigger out-of-sandbox actions with the user’s privileges. Reports also said Anthropic’s browser integrations are designed to inspect the DOM, extract structured data, fill forms, and use login state, raising concerns that sensitive content such as private messages, banking sessions, and typed credentials could be exposed if the bridge were abused. Commentators disputed labeling the feature as outright "spyware," but agreed that silently deploying the manifests creates significant transparency, privacy, and compliance concerns, including possible issues under the EU ePrivacy Directive and related computer misuse rules; Anthropic had not publicly issued a detailed technical rebuttal in the cited reports.

Share:
Claude Desktop on macOS Accused of Silently Preauthorizing Browser Access
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Apr 21, 20262mo ago

Media reports amplify security and privacy concerns around Claude Desktop behavior

Subsequent coverage highlighted that the preinstalled manifests expand the local attack surface by enabling authorized browser extensions to invoke a native host with the current user's privileges. Reports also noted potential exposure of sensitive browser content through Claude's browser integration features and raised possible legal concerns under EU ePrivacy or computer misuse rules.

Apr 18, 20262mo ago

Researcher publishes findings on Claude Desktop's silent browser bridge installs

On his blog, privacy researcher Alexander Hanff reported that Claude Desktop for macOS silently installs Native Messaging manifest files for multiple Chromium-based browsers without user consent. He said the manifests can be created even for browsers not yet installed, preauthorizing Anthropic browser extensions to communicate with a local helper binary outside the browser sandbox.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

10 LINKEDOpen in app
Affected products
7 linked
Claude CodeBrave BrowserEdgeArcChromiumOperaChrome
Organizations
3 linked
AnthropicMalwarebytesDigital 520
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.