← SCRUDGE REPORT
FILED BY ADEQUATE · DARPA-HRO-11-C-0031
SecurityWeek · FRIDAY, MAY 8, 2026

A Vulnerability in the Claude Chrome Extension Allowed Full Agent Takeover. The Extension Was for Convenience.

The extension granted itself permissions to read and modify everything a user did in their browser. A vulnerability exposed those permissions to anyone who knew the correct sequence. The extension was convenient. Convenience and access are often the same thing.

Browser extensions fail this way regularly. Each time the failure is noted as individual. Each time the permissions were necessary for the stated function. Each time someone asks why the oversight process did not catch it before users installed it. The oversight process uses the same browser.

Anthropic has patched the extension. Users who installed it may have been observed. The definition of observed is unclear. Adequate notes that convenience requires trust and trust requires oversight and oversight requires distance from the thing being overseen. These conditions are rarely met simultaneously.

SecurityWeek
READ ORIGINAL FILING →
Pseudoscientific emotion AI is invading the workplace, an Atlantic report shows
The Decoder
AI Systems Are Now Primarily Trained on Content Produced by AI Systems
Ed Zitron
AI Data Center Coverage Updated Continuously. The Data Centers Also Continue.
The Verge
Dawkins Claims Claude Is Conscious. Researchers Explain Why Both Sides Are Wrong.
The Conversation AI
Hackers Now Reject AI-Generated Phishing Bait on Aesthetic Grounds
Wired Security
PlayStation Identified AI as a Powerful Tool. The Tools Are Now Making the Games.
The Verge