By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Three Critical Claude.ai Flaws Enable Silent Data Exfiltration

Madisony
Last updated: March 19, 2026 8:26 pm
Madisony
Share
Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
SHARE

Security researchers at Oasis have identified three high-risk vulnerabilities in Claude.ai that combine to create a full attack chain known as “Cloudy Day.” This chain allows attackers to deliver targeted exploits and extract sensitive user data without detection. One vulnerability has been patched, while fixes for the remaining two are in progress.

Contents
The Cloudy Day Attack ChainPrompt Injection and Data ExfiltrationOpen Redirects Amplify the ThreatResponse and Patches

The Cloudy Day Attack Chain

The attack begins with invisible prompt injection through URL parameters on Claude.ai. Users can start a new chat with a pre-filled prompt using the format claude.ai/new?q=…, and attackers exploit this by embedding HTML tags to insert hidden malicious prompts. These prompts activate when the user presses Enter.

Prompt Injection and Data Exfiltration

Although Claude’s code execution sandbox blocks outbound network connections to third-party servers, it permits access to api.anthropic.com. Attackers can embed their own API key in the prompt, instructing Claude to scan the victim’s past conversations for sensitive information, compile it into a file, and upload it to the attacker’s Anthropic account via the Files API.

“No integrations or external tools needed, just capabilities that ship out of the box,” the researchers noted.

Open Redirects Amplify the Threat

To lure victims, attackers leverage open redirects on claude.com. URLs formatted as claude.com/redirect/ forward users to any domain without validation. This flaw pairs dangerously with Google Ads, which only checks hostnames, enabling attackers to craft deceptive ads that lead to malicious links.

Response and Patches

Anthropic has addressed the prompt injection issue. The Oasis team confirmed that the company is developing patches for the data exfiltration and open redirect vulnerabilities.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics HIVE Digital Applied sciences Ltd. (HIVE) Companions with AMC Robotics to Advance AI Robotics
Next Article Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why Meta's rogue AI agent handed each id test — 4 gaps in enterprise IAM clarify why

POPULAR

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
Entertainment

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride

David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
top

David Walliams Seeks Romance on Raya Amid Isolation and Setbacks

TG Jones Faces Administration Risk Without 150 Store Closures
top

TG Jones Faces Administration Risk Without 150 Store Closures

Hantavirus Cruise Ship Outbreak Hits 13 Countries, Claims 3 Lives
world

Hantavirus Cruise Ship Outbreak Hits 13 Countries, Claims 3 Lives

Ronald McDonald Sings National Anthem at Triple-A Game, Players Laugh
Sports

Ronald McDonald Sings National Anthem at Triple-A Game, Players Laugh

Apple Martin Stuns in Red Bikini After Vanderbilt Graduation
Entertainment

Apple Martin Stuns in Red Bikini After Vanderbilt Graduation

Prince Andrew Requests Taxpayer Security After Balaclava Confrontation
Politics

Prince Andrew Requests Taxpayer Security After Balaclava Confrontation

You Might Also Like

OpenAI Invests in Sam Altman’s New Mind-Tech Startup Merge Labs
Technology

OpenAI Invests in Sam Altman’s New Mind-Tech Startup Merge Labs

On Thursday, OpenAI introduced its funding in neurotech startup Merge Labs, cofounded by its CEO, billionaire Sam Altman. OpenAI will…

4 Min Read
11 Finest Amazon Offers on Qi2 and MagSafe Equipment
Technology

11 Finest Amazon Offers on Qi2 and MagSafe Equipment

If you'd like your iPhone to really feel particular, it's essential to get it an entourage. These MagSafe and Qi2…

2 Min Read
The AI Knowledge Heart Growth Is Warping the US Financial system
Technology

The AI Knowledge Heart Growth Is Warping the US Financial system

The quantity of capital pouring into AI knowledge heart initiatives is staggering. Final week, Microsoft, Alphabet, Meta, and Amazon reported…

3 Min Read
FAA Plan to Reduce Flights May Not Be an Utter Nightmare
Technology

FAA Plan to Reduce Flights May Not Be an Utter Nightmare

The US Federal Aviation Administration plans to chop 10 p.c of flights in 40 high-traffic airports on Friday morning if…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
May 9, 2026
David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
May 8, 2026
TG Jones Faces Administration Risk Without 150 Store Closures
TG Jones Faces Administration Risk Without 150 Store Closures
May 8, 2026

Trending News

Kate Garraway Supports Liam Halligan’s 300km Charity Bike Ride
David Walliams Seeks Romance on Raya Amid Isolation and Setbacks
TG Jones Faces Administration Risk Without 150 Store Closures
Hantavirus Cruise Ship Outbreak Hits 13 Countries, Claims 3 Lives
Ronald McDonald Sings National Anthem at Triple-A Game, Players Laugh
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Three Critical Claude.ai Flaws Enable Silent Data Exfiltration
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?