AW-026

Type: Connector disposition

Subject: Claude in Chrome (browser extension)

Decision requested: Approve the proposed disposition for Claude in Chrome (browser extension) across its 17 assessed actions

Inherent / residual: Critical / High

Control owner: InfoSec + IT (Chrome extension policy / MDM) + Claude Owner

Context: 17 assessed actions. No Claude runtime control on this path. Administrative actions proposed: Permit with restrictions x10, Permit x4, Do not enable x3. Proposed for Blocked: javascript_tool - execute arbitrary JavaScript in page context; read_network_requests - read HTTP traffic from the tab; Skip all permissions mode. Class: Browser extension (acts inside the user's authenticated browser session, with per-site permission grants). Control point: Extension site-permission settings (extension icon > Settings > Site Permissions), plus Chrome enterprise extension policy by MDM, plus Claude organization settings where the feature can be blocked for Team and Enterprise. Control owner: InfoSec + IT (Chrome extension policy / MDM) + Claude Owner.

Risks: R-11 [High inherent / Low residual] Substitution by unmanaged third-party MCP servers for the same services | R-27 [Critical inherent / High residual] Aggregate outbound surface across the estate | R-50 [High inherent / Moderate residual] The safe permission choice may not be the default one | R-51 [Critical inherent / High residual] The extension reaches whatever the browser is signed into | R-52 [Moderate inherent / Moderate residual] Reported defects in the persistence of site permission grants | R-53 [Critical inherent / High residual] Arbitrary script execution inside authenticated origins | R-54 [Critical inherent / High residual] Network and console observation exposes credentials the page never displays | R-55 [High inherent / Moderate residual] Saved workflows execute content defined outside this assessment

Open verification: V-44 [Critical] Which permission option is pre-selected in the deployed extension build when the site permission prompt appears, and whether allow-once requires an additional interaction such as opening a dropdown. Capture a screenshot as the baseline. The same question applies to the connector approval prompts more generally. | V-45 [Critical] Whether the extension is already installed anywhere; which sites currently hold always-allow for those users; whether Team or Enterprise organization settings block the feature; and whether skip-all-permissions mode can be prevented centrally rather than by policy alone. | V-46 [High] Whether always-allow grants persist as documented in the deployed build, whether the approved-sites list populates, and whether the permission dialog times out in a way that registers as a denial. | V-47 [Critical] Which tools the extension actually exposes to the surface your users have. This assessment observed arbitrary JavaScript execution, HTTP request reading, console reading, mouse and keyboard control, file upload, saved-workflow execution and multi-browser enumeration in the tool surface available to an agentic session. None of these appear in the support documentation describing the side panel. Establish whether the end-user experience exposes the same set, a subset, or something wider. | V-48 [Critical] Whether the organization falls within the vendor's stated exclusion of Claude in Chrome for organizations covered by HIPAA, and whether that statement is current. Confirm with the vendor directly rather than inferring from help-centre wording.

Ruling:

Amendment or condition: