Claude extension flaw allowed zero click attacks, letting hackers inject commands and access sensitive user data.
The exposed keys belonged to major service providers such as AWS, Stripe, and GitHub, and the potential damage ranged from ...