Researchers have identified three high-risk vulnerabilities in Claude.ai. These enable an end-to-end attack chain that exfiltrates sensitive information without the user's knowledge. A legitimate Google ad could trigger data exfiltration.
TechRadar reported on March 19, 2026, the discovery of three high-risk AI vulnerabilities in Claude.ai. The flaws form an end-to-end attack chain capable of exfiltrating sensitive information without the user knowing. Notably, a legitimate Google ad could lead to such data exfiltration. This security issue highlights risks in AI systems where external elements like ads can compromise user data.