ثغرتان فى Claude تسمحان بتشغيل 9 مهام حساسة دون موافقة

20 يوليو 2026·اليوم السابع
ثغرتان فى Claude تسمحان بتشغيل 9 مهام حساسة دون موافقة

كشف باحثون أمنيون عن ثغرتين غير مصححتين في إضافة Claude لمتصفح Chrome، قد تسمحان لإضافة خبيثة أخرى بتنفيذ نقرات وهمية وتشغيل مهام حساسة دون تدخل مباشر من المستخدم، وتزداد خطورة المشكلة عند منح Claude صلاحية تنفيذ المهام تلقائيًا، لأن الإضافة قد تتعامل مع البريد والمستندات والمواعيد دون طلب موافقة جديدة قبل كل خطوة.

نقرات وهمية تصل إلى البريد والمستندات

وفقًا لتقرير منشور في موقع تك رادار، اكتشف باحثو شركة مانيفولد سيكيوريتي أن إضافة Claude لا تتحقق بصورة كافية من أن النقرة نفذها شخص حقيقي، وهو ما يسمح لإضافة خبيثة بمحاكاة النقر وتشغيل 9 مهام مبرمجة، وتشمل هذه المهام قراءة رسائل Gmail، وفتح ملفات Google Docs، وفحص المواعيد المسجلة في Google Calendar، وتعديل بيانات العملاء داخل Salesforce، وحصلت الثغرة على درجة خطورة بلغت 7.7 من 10 في الإعدادات العادية، وترتفع إلى 9.6 عند تفعيل التنفيذ التلقائي.

المشكلة بقيت خلال 8 تحديثات

ترتبط الثغرة الثانية بجزء داخل الرابط المستخدم لفتح اللوحة الجانبية لإضافة Claude، إذ يمكن التلاعب به لتجاوز طلب الموافقة الذي يظهر قبل تنفيذ المهمة، وقال الباحثون إن عملية التجاوز لا تحتاج إلا إلى 6 أسطر مكتوبة بلغة JavaScript، كما وجدوا أن الأجزاء البرمجية المسؤولة عن المشكلة ظلت دون تغيير خلال 8 تحديثات متتالية، وأبلغ الفريق شركة Anthropic بالثغرتين، لكنهما بقيتا موجودتين في الإصدار الذي اختبره الباحثون.
 



ClaudesecurityChrome
الخبر متوفّر باللغات التالية:English
المصدر الأصلي للخبر
اليوم السابع

Two Flaws in Claude Allow for the Execution of 9 Sensitive Tasks Without Consent

July 20, 2026·Youm7
Two Flaws in Claude Allow for the Execution of 9 Sensitive Tasks Without Consent

Security researchers have exposed two unpatched vulnerabilities in the Claude extension for Chrome, which could allow a malicious extension to execute simulated clicks and run sensitive tasks without direct user intervention. The problem becomes more serious when Claude is granted automatic task execution permissions, as the extension may handle emails, documents, and appointments without seeking new consent before each step.

Simulated Clicks Reach Emails and Documents

According to a report published on TechRadar, researchers from Manifold Security discovered that the Claude extension does not sufficiently verify that the click was performed by a real person. This allows a malicious extension to simulate a click and execute 9 pre-programmed tasks, including reading Gmail messages, opening Google Docs files, checking appointments in Google Calendar, and modifying customer data within Salesforce. The vulnerability has been rated as high-risk (7.7 out of 10) in normal settings, but it rises to 9.6 when automatic execution is enabled.

The Problem Persisted Through 8 Updates

The second vulnerability relates to a part within the link used to open Claude’s sidebar. It can be manipulated to bypass the consent request that appears before executing a task. The researchers said that bypassing this process requires only six lines of JavaScript code. They also found that the code segments responsible for the problem remained unchanged through eight consecutive updates. The team reported both vulnerabilities to Anthropic, but they persisted in the version tested by the researchers.


ClaudesecurityChrome
This article is also available in:العربية
Original source article
Youm7