YOU ARE VIEWING ONE ITEM FROM THE AICRIER FEED

Claude Desktop hits backlash over silent "spyware bridge"

AICrier tracks AI developer news across Product Hunt, GitHub, Hacker News, YouTube, X, arXiv, and more. This page keeps the article you opened front and center while giving you a path into the live feed.

// WHAT AICRIER DOES

7+

TRACKED FEEDS

24/7

SCRAPED FEED

Short summaries, external links, screenshots, relevance scoring, tags, and featured picks for AI builders.

Claude Desktop hits backlash over silent "spyware bridge"
OPEN LINK ↗
// 45d agoSECURITY INCIDENT

Claude Desktop hits backlash over silent "spyware bridge"

Anthropic's "safety-first" reputation is under fire following reports that Claude Desktop silently installs Native Messaging manifests across multiple Chromium-based browsers without user consent. These files pre-authorize Anthropic's browser extensions to execute code outside the browser sandbox, potentially exposing sensitive DOM data and login sessions to "computer use" agents.

// ANALYSIS

Anthropic's silent installation of a dormant "spyware bridge" is a massive trust violation for an AI lab that markets itself on constitutional safety. The app automatically writes JSON manifests to browser support folders to enable out-of-sandbox execution, allowing it to read raw DOM data and potentially hijack browser sessions. Installing these manifests for browsers not present on the system is clear overreach. This dormant capability should be strictly opt-in; reaching across trust boundaries without notification is a breach of security etiquette. Security-conscious developers are recommending users run Claude Desktop in a VM or Docker sandbox to prevent it from "hoovering up" local credentials and browser context.

// TAGS
claude-desktopanthropicsecurityprivacysafetycomputer-use

DISCOVERED

45d ago

2026-04-20

PUBLISHED

45d ago

2026-04-20

RELEVANCE

8/ 10

AUTHOR

know-your-enemy-92