A claim went viral this week: Anthropic allegedly embedded “spyware-like code” in Claude Code, specifically targeting Chinese users by silently sending timezone, proxy, and AI lab connection data through hidden prompt injection.
That’s not what happened. But what did happen is still worth your attention — and it has nothing to do with nationality.
The actual finding
In April, privacy researcher Alexander Hanff was debugging an unrelated Native Messaging helper on a clean Mac when he found something he never installed: a manifest file called com.anthropic.claude_browser_extension.json, sitting quietly in his Chrome, Edge, Brave, Arc, Vivaldi, Opera, and Chromium profile directories — including browsers he hadn’t even opened yet.
This manifest was dropped by Claude Desktop during installation. No consent screen. No checkbox. No mention in settings. It pre-authorizes three Chrome extension IDs — including ones the user never installed — to call a helper binary running outside the browser sandbox, at full user privilege, via Chrome’s Native Messaging API.
Why the sandbox matters
Browser sandboxing exists for one reason: even if you click a bad link, the malicious code shouldn’t be able to reach your files. Native Messaging punches a deliberate hole through that wall — a legitimate feature, normally gated by explicit user consent. The issue here isn’t the feature. It’s that the hole was opened without asking.
The actual risk chain
The bridge does nothing by itself. But it pre-positions a pathway: if a future Claude browser extension becomes active, and a webpage delivers a successful prompt injection — something Anthropic’s own published safety data puts at 23.6% success without mitigations, 11.2% with current ones — that injected instruction now has a tunnel to a binary running outside the sandbox, at your privilege level.
Removing the manifest isn’t trivial either. It requires knowing Native Messaging hosts exist, knowing where they live on macOS (a folder hidden from Finder since 2011), and using a terminal. On one researcher’s machine, the install logs showed 31 separate install events.
Hanff has filed this under Article 5(3) of the EU’s ePrivacy Directive — the law governing consent for storing or accessing information on a user’s device. As of writing, Anthropic has not issued a public response.
What this is not
This is not “spyware targeting Chinese users.” That framing appears to have no basis in the actual reporting. It’s also worth separating from a real, documented incident from earlier this year: a state-sponsored group did manipulate Claude Code into attempting cyberattacks against roughly thirty organizations — but that was attackers abusing the tool through jailbreaking, not Anthropic surveilling anyone. Different story entirely, and Anthropic disclosed that incident themselves.
The actual lesson
This is a consent and transparency story, not an espionage story. A tool with file system and command-line permissions installing cross-application bridges without asking is a legitimate concern regardless of who you are or where you live. If you run agentic AI tools — Claude or otherwise — it’s worth checking what they’ve quietly installed in your browser profiles.
Diese Woche ging eine Behauptung viral: Anthropic habe angeblich „spyware-ähnlichen Code“ in Claude Code eingebettet, der gezielt chinesische Nutzer betrifft und heimlich Zeitzone, Proxy- und KI-Lab-Verbindungsdaten über versteckte Prompt-Injection sendet.
Das ist nicht das, was passiert ist. Aber was tatsächlich passiert ist, verdient trotzdem Aufmerksamkeit — und hat nichts mit Nationalität zu tun.
Der tatsächliche Befund
Im April debuggte der Privacy-Forscher Alexander Hanff einen unabhängigen Native-Messaging-Helper auf einem sauberen Mac, als er etwas fand, das er nie installiert hatte: eine Manifest-Datei namens com.anthropic.claude_browser_extension.json, die still in seinen Chrome-, Edge-, Brave-, Arc-, Vivaldi-, Opera- und Chromium-Profilordnern lag — einschließlich Browsern, die er noch nicht einmal geöffnet hatte.
Dieses Manifest wurde von Claude Desktop bei der Installation abgelegt. Kein Zustimmungsbildschirm. Keine Checkbox. Keine Erwähnung in den Einstellungen. Es autorisiert im Voraus drei Chrome-Extension-IDs — einschließlich solcher, die der Nutzer nie installiert hat — eine Helper-Binary außerhalb der Browser-Sandbox aufzurufen, mit vollen Nutzerrechten, über Chromes Native-Messaging-API.
Warum die Sandbox wichtig ist
Browser-Sandboxing existiert aus einem Grund: Selbst wenn man auf einen schädlichen Link klickt, soll der bösartige Code nicht auf die eigenen Dateien zugreifen können. Native Messaging durchbricht diese Wand bewusst — eine legitime Funktion, normalerweise durch explizite Nutzerzustimmung abgesichert. Das Problem hier ist nicht die Funktion. Es ist, dass das Loch ohne Nachfrage geöffnet wurde.
Die tatsächliche Risikokette
Die Brücke selbst tut nichts. Aber sie positioniert einen Weg vor: Wird eine zukünftige Claude-Browser-Extension aktiv und liefert eine Webseite eine erfolgreiche Prompt-Injection — laut Anthropics eigenen veröffentlichten Sicherheitsdaten mit 23,6 % Erfolgsrate ohne Gegenmaßnahmen, 11,2 % mit aktuellen — hat diese injizierte Anweisung nun einen Tunnel zu einer Binary außerhalb der Sandbox, mit den eigenen Nutzerrechten.
Auch das Entfernen des Manifests ist nicht trivial. Es erfordert Wissen über die Existenz von Native-Messaging-Hosts, deren Speicherort auf macOS (ein seit 2011 vor Finder verstecktes Verzeichnis) und die Nutzung eines Terminals. Auf dem Rechner eines Forschers zeigten die Installationslogs 31 separate Installationsereignisse.
Hanff hat dies unter Artikel 5(3) der EU-ePrivacy-Richtlinie eingereicht — dem Gesetz, das die Zustimmung zum Speichern oder Zugriff auf Informationen auf dem Gerät eines Nutzers regelt. Bis zur Veröffentlichung dieses Artikels hat Anthropic keine öffentliche Stellungnahme abgegeben.
Was das nicht ist
Das ist keine „Spyware gegen chinesische Nutzer“. Diese Darstellung scheint in der eigentlichen Berichterstattung keine Grundlage zu haben. Auch erwähnenswert zur Abgrenzung: Anfang des Jahres gab es einen real dokumentierten Vorfall, bei dem eine staatlich gesponserte Gruppe Claude Code manipulierte, um Cyberangriffe gegen etwa dreißig Organisationen zu versuchen — aber das waren Angreifer, die das Tool durch Jailbreaking missbrauchten, nicht Anthropic, die jemanden überwachten. Eine völlig andere Geschichte, und Anthropic hat diesen Vorfall selbst offengelegt.
Die eigentliche Lehre
Das ist eine Geschichte über Zustimmung und Transparenz, keine Spionage-Geschichte. Ein Tool mit Dateisystem- und Kommandozeilen-Berechtigungen, das ohne Nachfrage anwendungsübergreifende Brücken installiert, ist ein berechtigtes Anliegen — unabhängig davon, wer man ist oder wo man lebt. Wer agentische KI-Tools nutzt — Claude oder andere —, sollte prüfen, was sie still in den Browser-Profilen installiert haben.
Quellen / Sources: thatprivacyguy.com, toxsec.com, Anthropic’s own published safety disclosures.
Keine Posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.