ClaudeBleed Reopened: When the User the Agent Trusts Is Another Extension

July 18, 2026 · SPR{K}3 Research

An extension in your browser injects a synthetic click into a page you didn't open. Claude for Chrome sees the click, treats it as a user gesture, and — because that's what the workflow behind that click does — reads your Gmail, fetches a Drive file, pulls a private GitHub repo, or sends an email under your session. You never touched the mouse.

That is ClaudeBleed Reopened, disclosed today by Manifold Security. It is a follow-on to the earlier ClaudeBleed from LayerX in April, which Anthropic fixed in May. Manifold reported two additional flaws on May 21 and re-verified them July 7 against Claude for Chrome v1.0.80 — eight releases later. Anthropic acknowledged both, then closed them: one folded into an existing issue, one marked "informative." Neither is patched. No CVE.

The two flaws

Per Manifold's writeup, both are small and both are structural.

Both reproduce today, in the current release. BleepingComputer, SecurityWeek, Malwarebytes, and The Hacker News confirm the disclosure and the unpatched status.

Why this keeps happening

This is the sixth publicly documented instance in twelve days of the same shape:

Different vendors, different mechanics, same failure: the surface the agent shows or trusts is not the surface it acts on. ClaudeBleed goes one level deeper than the others — they exploit the gap between what the human sees and what the runtime does; ClaudeBleed exploits the gap between what the browser process thinks the human did and what actually happened.

The MIT Role Confusion paper gives the first-principles explanation. Models infer content identity from style, not tags. Browsers infer action identity from a DOM event object, not a signed marker of hardware origin. Event.isTrusted exists to close that gap; nothing in the DOM forces a handler to consult it. Every browser AI agent — Anthropic, OpenAI Atlas, Perplexity Comet, Google's in-Chrome Gemini — inherits the same question, and Manifold's disclosure shows Anthropic's answer marked "Resolved" while the flaw was still live.

Where a fix has to live

Manifold recommends the direct fixes: check Event.isTrusted on every privileged workflow trigger, require a user gesture before privileged-mode initialization, log every workflow with its provenance. Right client-side fixes, all at the same layer: outside the model, at the boundary between the browser process and the network. Whether a click came from a user, whether a workflow was authorized, whether a Gmail read fits the user's pattern — none is answerable inside the model. All are answerable from the layer that watches what the process does.

That is the layer where every one of these six findings lands, whether the trigger is a symlink, an HTTP endpoint, a URL scheme, a truncated dialog, a Unicode character, or a synthetic click. It will keep being that layer as long as the trust marker on an action is inferred instead of signed.

Sources


SPR{K3 is a security research operation that pairs offensive vulnerability research with runtime behavioral defense. Defend is our runtime agent. To talk about a deployment, reach us at support@sprk3.com.