By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Three Critical Claude.ai Flaws Enable Silent Data Exfiltration

Madisony
Last updated: March 19, 2026 8:26 pm
Madisony
Share
Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
SHARE

Security researchers at Oasis have identified three high-risk vulnerabilities in Claude.ai that combine to create a full attack chain known as “Cloudy Day.” This chain allows attackers to deliver targeted exploits and extract sensitive user data without detection. One vulnerability has been patched, while fixes for the remaining two are in progress.

Contents
The Cloudy Day Attack ChainPrompt Injection and Data ExfiltrationOpen Redirects Amplify the ThreatResponse and Patches

The Cloudy Day Attack Chain

The attack begins with invisible prompt injection through URL parameters on Claude.ai. Users can start a new chat with a pre-filled prompt using the format claude.ai/new?q=…, and attackers exploit this by embedding HTML tags to insert hidden malicious prompts. These prompts activate when the user presses Enter.

Prompt Injection and Data Exfiltration

Although Claude’s code execution sandbox blocks outbound network connections to third-party servers, it permits access to api.anthropic.com. Attackers can embed their own API key in the prompt, instructing Claude to scan the victim’s past conversations for sensitive information, compile it into a file, and upload it to the attacker’s Anthropic account via the Files API.

“No integrations or external tools needed, just capabilities that ship out of the box,” the researchers noted.

Open Redirects Amplify the Threat

To lure victims, attackers leverage open redirects on claude.com. URLs formatted as claude.com/redirect/ forward users to any domain without validation. This flaw pairs dangerously with Google Ads, which only checks hostnames, enabling attackers to craft deceptive ads that lead to malicious links.

Response and Patches

Anthropic has addressed the prompt injection issue. The Oasis team confirmed that the company is developing patches for the data exfiltration and open redirect vulnerabilities.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics
Next Article Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why

POPULAR

Invesco High Yield Fund Gains 1.31% in Q4 2025 Amid Rate Cuts
business

Invesco High Yield Fund Gains 1.31% in Q4 2025 Amid Rate Cuts

Proven Petrol Hacks to Slash Costs as Prices Surge in Australia
top

Proven Petrol Hacks to Slash Costs as Prices Surge in Australia

Mahmood Pushes Swift Deportations for Failed Asylum Seekers
top

Mahmood Pushes Swift Deportations for Failed Asylum Seekers

Trump Shares SNL Skit Mocking Starmer Over Gulf Warship Fears
Politics

Trump Shares SNL Skit Mocking Starmer Over Gulf Warship Fears

Student Loans Cut UK Home Deposit Savings by £2,000 Yearly
business

Student Loans Cut UK Home Deposit Savings by £2,000 Yearly

ABC Strike Looms: Thousands Walk Off in Pay Dispute
top

ABC Strike Looms: Thousands Walk Off in Pay Dispute

Logan Paul Mocks Tom Brady with Sarcastic Flag Football Apology
Sports

Logan Paul Mocks Tom Brady with Sarcastic Flag Football Apology

You Might Also Like

How you can Prep for This Weekend’s Large Winter Storm: Energy, Warmth, and Underwear
Technology

How you can Prep for This Weekend’s Large Winter Storm: Energy, Warmth, and Underwear

The Winter storm has no title. However a storm is coming, An excessive winter climate system is anticipated to maneuver…

29 Min Read
Hypershell Professional X Sequence Evaluate: An Exoskeleton You Can Really Purchase
Technology

Hypershell Professional X Sequence Evaluate: An Exoskeleton You Can Really Purchase

WIRED Editor Amit Katwala has traveled far and broad for a hands-on take a look at the way forward for…

5 Min Read
Canon Promo Codes: 10% Off | August 2025
Technology

Canon Promo Codes: 10% Off | August 2025

We love Canon’s lineup of mirrorless cameras, which ship the identical nice picture high quality with out the majority. The…

10 Min Read
The way to Handle Recordsdata on iOS and Android
Technology

The way to Handle Recordsdata on iOS and Android

One of many modifications that we have seen in telephones over current years has been extra management over the file…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Invesco High Yield Fund Gains 1.31% in Q4 2025 Amid Rate Cuts
Invesco High Yield Fund Gains 1.31% in Q4 2025 Amid Rate Cuts
March 23, 2026
Proven Petrol Hacks to Slash Costs as Prices Surge in Australia
Proven Petrol Hacks to Slash Costs as Prices Surge in Australia
March 23, 2026
Mahmood Pushes Swift Deportations for Failed Asylum Seekers
Mahmood Pushes Swift Deportations for Failed Asylum Seekers
March 23, 2026

Trending News

Invesco High Yield Fund Gains 1.31% in Q4 2025 Amid Rate Cuts
Proven Petrol Hacks to Slash Costs as Prices Surge in Australia
Mahmood Pushes Swift Deportations for Failed Asylum Seekers
Trump Shares SNL Skit Mocking Starmer Over Gulf Warship Fears
Student Loans Cut UK Home Deposit Savings by £2,000 Yearly
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?