Security Alert: Claude Plugins Become a Platform for Malware, Google Calendar Becomes an Attack Entry Point
Israeli security company LayerX discovered a critical vulnerability in Claude Desktop Extensions, allowing attackers to achieve 'zero-click' remote code execution through Google Calendar invites, with a CVSS score of 10/10. The vulnerability stems from Claude's automatic processing of external connector inputs, enabling malicious commands to be triggered through calendar events.