Zero-Click RCE Vulnerability in Claude Desktop Extensions Exposes 10,000+ Users

Thumbnail Image

The information displayed in the AIM should not be reported as representing the official views of the OECD or of its member countries.

A critical zero-click remote code execution vulnerability in Anthropic's Claude Desktop Extensions allows attackers to compromise over 10,000 users' systems via malicious Google Calendar events. The flaw stems from unsafe AI architecture granting extensions full system privileges without proper sandboxing. Anthropic has declined to fix the issue despite its severity.[AI generated]

Why's our monitor labelling this an incident or hazard?

The event involves an AI system (Claude Desktop Extensions) that processes inputs from Google Calendar and autonomously executes commands via extensions with system-level access. The vulnerability allows attackers to send malicious calendar events that the AI will execute without user consent, causing direct harm through remote code execution (malware infection). This meets the definition of an AI Incident because the AI system's use and malfunction have directly led to harm to property (user systems) and pose significant security risks. The developer's refusal to fix the issue does not negate the realized harm potential. Therefore, this is classified as an AI Incident.[AI generated]
AI principles
Robustness & digital securityAccountability

Industries
Digital security

Affected stakeholders
Consumers

Harm types
Economic/Property

Severity
AI incident

AI system task:
Interaction support/chatbots


Articles about this incident or hazard