[BUG] Security violations in Claude Code Extension
Preflight Checklist
- [x] I have searched existing issues and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code
What's Wrong?
The chrome-extension://fcoeoabgfenejglbffodgkkbkcdhcgfn has significant privacy concerns: Presently Claude Code can view whatever it likes in Normal or Incognito and that isnt in any way prevented.
1/ There's no way to stop it browsing whatever it likes, even the Cancel button doesnt work, The button shouldnt just be Cancel, it should "Permanantly Prevent Claude from accessing this Page"
2/ In the the actual extension settings of Chrome/Brave it has "This can read or change site data"... a) on when I click the extension b) On <website> c) On all sites. In must have at this browser level d) Prevent from accessing <website>.
3/ In claudes own extension setting must also be a list of a) browser types it can and cannot access - Standard/Incognito b) A list of sites its banned from (and it can never go there), c) A rule- (i)Deny access to all sites except those granted access (ii) Approve access to all sites except those specifically banned.
Since Claude can do whatever it likes, please get this done ASAP
What Should Happen?
Immediately change the claude extension.
Error Messages/Logs
Claude can access whatever open tabs it likes, including those we Cancel its access to.
Steps to Reproduce
Do as I already stated
Claude Model
None
Is this a regression?
I don't know
Last Working Version
_No response_
Claude Code Version
This related to the Chrome extension
Platform
Anthropic API
Operating System
Ubuntu/Debian Linux
Terminal/Shell
Terminal.app (macOS)
Additional Information
as already discussed