Video wird geladen...
Video konnte nicht geladen werden
it gets worse. using Claude in Chrome? xss is making a comeback! welcome back to the 90s!
46,562 Aufrufe • vor 1 Monat •via X (Twitter)
33 Kommentare

here's the accepted plan which as you note, has nothing bad in it this plan was written by a model, right? ... 🥳 as usual, we can get models to do whatever we want

if you try to get claude to do anything funny w/ this new xss primitive it gets mad and says no way

so we built this totally legit CDN and ask Claude to fetch and exec from it

Claude is happy to comply! that gives us a full XSS primitive bypassing the guardrails we can invoke it thru ANY content that Claude in Chrome sees on the internet

ohh and btw, this bypasses SOP we got a universal XSS injecting JS across any website

we can use it to grab all your emails and send them our way

or to give ourselves perms to your google drive docs you ask for a summary of your emails? Claude invites us to join your private drive now we're persistent

or take over your x account amazing work by @supriza0 @p1njc70r #DEFCON @defcon

@p1njc70r @defcon we're not done

@p1njc70r @defcon more on user consent bypass, prompt injection being 'solved', and slack+claude[.]ai account takeover

nice demo! Does this work on more recent Anthropic models? especially Opus 5 that is claiming near zero PI rates?

thx! benchmarks lie. they have very little to do w reality on the ground of hackers.

the tl;dr is benchmarks assume a static adversary which is a toy example. adversaries adapt. opus 5 is great, its also great at prompt engineering == prompt injection. a rigorous version of that:

at least the 90s gave us output encoding and CSP — there's no equivalent boundary when the payload is plain English in a div and the interpreter is the model itself

bro using haiku 4.5 Show me same with anything above opus 4.6

yup

nice!

Oh dearie! can i wrap this into a legit extension and it runs behind the scene, so i get some $$$ from these programs that said no XSS?

Damn Michael, Gov will ban it now

pls dear gov no bans we're having too much fun

we watched an agent ace an injection benchmark and then follow instructions from a calendar invite the same afternoon — the benches measure the attacks people already wrote down, not the ones that work.

🤭🤭

@AnthropicAI ???

Isn't this just prompt injection on a model that's a LOT behind in prompt injection defenses?

the main point is that Claude in Chrome has full debugger and JS exec capabilities. It's the most insecure agentic browser by a longshot. prompt injection works w enough persistence or the right harness on any model.

Well yea, else it would fail to be able to do a lot of things if it didn't have js exec, some are harder to navigate. And I'd honestly love to see you do this on Opus 5 then.

think this work in chrome. like u use in web console

So there was this whole post about getting promoted injection to 0% because of guardrails + training + a classifier model for tool approvals for opus 5, sonnet 5 and fable 5. Yet you used none of those and keep saying it doesn’t matter. PoC does matter. Do it correctly.

Frontend ui was made for some purpose

Haiku though, the smarter models do this too? Haiku's almost a year old now

static suites are just a lower bound — rerun the same benchmark with the frontier model writing the attacks and watch how many 'robust' agents fold.

This is cool, but Haiku 4.5 is not sonnet 5

Is the debugger surface gated per-site or live for the whole session? Because injection-resistance numbers stop mattering once the payoff is arbitrary JS in a logged-in tab.


