The Chrome, iMessage, and Apple Notes connectors were vulnerable to command injection attacks that could transform a simple user question into complete system compromise.
The vulnerability stems from unsanitized command injection, a fundamental security flaw that developers have understood for decades.
Unlike malware requiring installation or phishing attacks requiring user interaction, this flaw could be exploited through normal Claude interactions.
When a user asked Claude a simple question like “Where can I play paddle in Brooklyn?”, that question could trigger arbitrary code execution if the search results contained specially crafted malicious payloads.
SSH keys, AWS credentials, and browser passwords could all be exposed with no user awareness of the attack.
Anthropic confirmed all three extensions as high-severity vulnerabilities with a CVSS score of 8.9, though patches have since been released.
However, the implications extend far beyond these three extensions, revealing systemic risks in the emerging MCP ecosystem.
Claude Desktop Extensions, distributed as .mcpb bundles, run fully unsandboxed with complete system permissions, unlike Chrome extensions, which operate in sandboxed environments.
Each vulnerable extension accepted user input through AppleScript commands without escaping or validation, allowing attackers to inject malicious code by breaking out of string contexts.
When Claude fetched web pages to answer questions, attacker-controlled sites could inject prompt payloads that exploited these extensions, establishing a direct chain from remote content to local code execution.
The real concern extends beyond these three official extensions. The MCP ecosystem is expanding rapidly with independent developers creating new extensions, many using AI-assisted coding with minimal security review.
This combination of full local access, rapid iteration cycles, and limited oversight creates a significant attack surface.
These vulnerabilities represent not an isolated incident but a warning signal about the security maturity of AI desktop integration frameworks.
Users must understand that MCP extensions operate fundamentally differently from traditional browser add-ons; they execute with system-level privileges and require proportionally higher security scrutiny.
Cyber Awareness Month Offer: Upskill With 100+ Premium Cybersecurity Courses From EHA's Diamond Membership: Join Today
The post Critical Remote Code Execution Flaws Found in Claude Desktop Application appeared first on Cyber Security News.
The "vast majority" of Bungie staff was reportedly unaware of the plans to discontinue support…
Earlier this year, Apple released its 8th generation iPad Air tablet at a starting price…
According to the Alzheimer’s Association, nearly 7.4 million Americans suffer from the disease, with the…
A North Korea-linked hacker group has quietly upgraded one of its most dangerous tools, making…
A well-known advanced persistent threat group called Cloud Atlas has been caught using a dangerous…
Tekken director Katsuhiro Harada finally found the time to take a trip to Waffle House.…
This website uses cookies.