[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$foj_-dIYtqfwOlotdKhzDUYTYHlVjoRMFkWZIxd2oYl0":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"3fca8837-8844-4d99-8e6c-00af0be1ae31","third-party-component-vulnerability-enables-silent-ai-prompt-injection","3177babd-0c78-4b0f-bf06-c3b3cc88ea18","Third-Party Component Vulnerability Enables Silent AI Prompt Injection","A critical vulnerability in Anthropic's Claude Chrome extension combined two security flaws: an overly permissive origin allowlist and a DOM-based XSS vulnerability in a third-party Arkose Labs CAPTCHA component. This chain allowed any website to silently inject malicious prompts into the AI assistant without user knowledge, potentially stealing credentials and accessing sensitive conversation history. The incident demonstrates how vulnerabilities in third-party dependencies can create severe security risks, especially when combined with misconfigurations in the primary application.","**Immediate actions:**\n- This incident could have been prevented through rigorous third-party component security assessment and regular vulnerability scanning of all dependencies\n\n**Long-term improvements:**\n- Implementing a strict Content Security Policy (CSP) and principle of least privilege for origin allowlists would have limited the attack surface\n\n**Detection measures:**\n- Regular security audits of the extension's integration points, automated dependency vulnerability monitoring, and coordinated disclosure processes between vendors could have identified and addressed these issues before exploitation",[12,13,14,15,16],"CIS Control 2","CIS Control 7","NIST SP 800-161","NIST AC-6","OWASP ASVS V14","published","2026-03-26T15:09:47.640196+00:00","2026-03-26T15:09:47.527+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F03\u002Fclaude-extension-flaw-enabled-zero.html","claude-extension-flaw-enabled-zero-click-xss-prompt-injection-via-any-website","Claude Extension Flaw Enabled Zero-Click XSS Prompt Injection via Any Website",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":32,"name":33,"slug":34,"description":35,"color":36},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]