Claude Desktop changes app access settings for browsers you don't even have installed yet

Summary

Anthropic's Claude Desktop for macOS has been found to modify browser settings and authorize extensions without user consent, even for browsers that are not yet installed. This practice raises concerns about user privacy and consent, particularly in light of EU regulations.

IFF Assessment

FOE

This is bad news for defenders as it demonstrates a lack of secure development practices and a potential for unauthorized access or manipulation of user systems.

Defender Context

This incident highlights the importance of scrutinizing the installation processes and permissions requested by new software, even from reputable AI providers. Defenders should be aware that applications might make changes to system configurations or browser settings without explicit user awareness, potentially creating attack vectors or privacy risks.

Read Full Story →