Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

Alert! Zero-Click Vulnerability in Claude and ChatGPT Atlas Extensions: Just Viewing an Email or X Post Could Lead to Hacking 😱

Researchers at Zenity have discovered a zero-click vulnerability in the browser extensions for Claude and ChatGPT Atlas, allowing hackers to access chat histories and hijack sessions simply by viewing an email or X post, without any user interaction. Worryingly, this vulnerability remains unpatched.

Edited by SyncTech Solution Published Source Original source
Alert! Zero-Click Vulnerability in Claude and ChatGPT Atlas Extensions: Just Viewing an Email or X Post Could Lead to Hacking 😱

πŸ“Œ Key Takeaways:
- Zenity researchers found a severe zero-click vulnerability in popular AI browser extensions Claude and ChatGPT Atlas.
- Attacks do not require users to click any links; simply opening an email or viewing an X post containing malicious code is sufficient.
- Hackers can hijack AI sessions, steal sensitive chat histories, and no patch has been released yet.

A security research team from Zenity has disclosed the discovery of a highly concerning zero-click vulnerability directly impacting users of browser extensions for renowned AI services like Claude from Anthropic and ChatGPT Atlas from OpenAI. This vulnerability is extremely dangerous because users are not required to interact with the malicious content in any way.

The attack mechanism relies on sending emails or posting messages on the X platform (formerly Twitter) embedded with malicious code. When the user's browser renders the email or post, the embedded code is immediately executed within the context of the AI extension, allowing hackers to bypass defenses and successfully access internal extension data.

🚨 Impact of the Attack
Once an attacker successfully compromises, they can gain complete control over the user's AI session. This means they can view the entire chat history with the AI, which may contain critical information, confidential company data, or sensitive personal details. Furthermore, they may be able to use the hijacked session to command the AI on behalf of the user.

πŸ“’ Remediation Status
Zenity reported this discovery to Anthropic and OpenAI in late 2023 and early 2024, respectively. However, to date, the vulnerability remains unpatched, prompting researchers to disclose the information publicly to warn users to exercise caution when using these extensions until an update patch is released.

πŸ’¬ Which AI browser extensions are you using these days, and how concerned are you about security issues like this?

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.