Anthropic’s Claude Desktop for macOS has been accused of silently installing Native Messaging manifest files that preauthorize its browser extensions to communicate with a local helper binary across multiple Chromium-based browsers, including Chrome, Brave, Edge, Arc, Vivaldi, and Opera. Researcher Alexander Hanff reported that the manifests can be written even for browsers not currently installed, meaning future Chromium-based browsers added to the system could automatically inherit the trust relationship. The manifests reportedly authorize specific extension IDs to access a local executable outside the browser sandbox, creating a persistent browser-to-local bridge without clear user notification or consent.
Security researchers said the behavior expands the host attack surface because a compromised or maliciously updated authorized extension could potentially trigger out-of-sandbox actions with the user’s privileges. Reports also said Anthropic’s browser integrations are designed to inspect the DOM, extract structured data, fill forms, and use login state, raising concerns that sensitive content such as private messages, banking sessions, and typed credentials could be exposed if the bridge were abused. Commentators disputed labeling the feature as outright "spyware," but agreed that silently deploying the manifests creates significant transparency, privacy, and compliance concerns, including possible issues under the EU ePrivacy Directive and related computer misuse rules; Anthropic had not publicly issued a detailed technical rebuttal in the cited reports.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Subsequent coverage highlighted that the preinstalled manifests expand the local attack surface by enabling authorized browser extensions to invoke a native host with the current user's privileges. Reports also noted potential exposure of sensitive browser content through Claude's browser integration features and raised possible legal concerns under EU ePrivacy or computer misuse rules.
On his blog, privacy researcher Alexander Hanff reported that Claude Desktop for macOS silently installs Native Messaging manifest files for multiple Chromium-based browsers without user consent. He said the manifests can be created even for browsers not yet installed, preauthorizing Anthropic browser extensions to communicate with a local helper binary outside the browser sandbox.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcemalwarebytes.com
Open sourceghacks.net
Open sourcethatprivacyguy.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.