Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Arkose Labs

Arkose Labs Vendor Cyber Rating & Cyber Score

arkoselabs.com

Arkose Labs helps the biggest enterprises in the world—including top banks, tech giants, social media platforms, airlines, etc.—protect their users, revenue and reputation from sophisticated cyberattacks, online fraud and scams. The company's Arkose Titan platform defends enterprises from human and AI-powered fraud, scraping and bot attacks. Unlike fragmented point solutions, Arkose Titan provides defense-in-depth through intelligent detection and adaptive mitigation against both traditional and emerging AI threats, including agentic AI. By defending a company’s entire digital experience and customer journey, Arkose Titan makes attacks economically unsustainable for perpetrators. It helps companies build their businesses uninterrupted and


Arkose Labs A.I CyberSecurity Scoring

Arkose Labs
Company Information
Website:https://www.arkoselabs.com/?utm_source=linkedin&utm_medium=social
Employees number:250
Number of followers:16,424
NAICS:541514
Industry Type:Computer and Network Security
Homepage:arkoselabs.com
Arkose Labs Risk Score (AI oriented)
Between 750 and 799
logo
Arkose LabsComputer and Network Security
Updated:
27/03/2026
752/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Arkose Labs Global Score (TPRM)
xxxx
logo
Arkose LabsComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Arkose Labs
Arkose LabsFair
Current Score
752Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752Before Incident
MAY 2026
752Before Incident
APRIL 2026
752Before Incident
MARCH 2026
752Before Incident
FEBRUARY 2026
751Before Incident
JANUARY 2026
751Before Incident
DECEMBER 2025
752Before Incident
Vulnerability
26 Dec 2025Arkose Labs
Anthropic and Arkose Labs: Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks

Critical Zero-Click Vulnerability in Claude Chrome Extension Exposed 3M Users to Silent Hijacking

751After Incident
CRITICAL-1
ANTARK1774585435
Critical Zero-Click Vulnerability in Claude Chrome Extension Exposed 3M Users to Silent Hijacking A now-patched zero-click vulnerability in Anthropic’s Claude Chrome Extension left over 3 million users vulnerable to silent prompt-injection attacks, enabling malicious actors to hijack the AI assistant without any user interaction. The exploit, discovered by KOI Security, could have allowed attackers to steal Gmail access tokens, read Google Drive files, export chat histories, and send emails all invisibly. The attack chain leveraged two critical flaws: 1. Overly Permissive Origin Allowlist – The extension’s messaging API accepted prompts from any `.claude.ai` subdomain, including third-party components like Arkose Labs’ CAPTCHA verification*, which was hosted on `a-cdn.claude.ai`. 2. DOM-Based XSS in Arkose CDN – An older, predictable version of the CAPTCHA component contained an unsanitized `stringTable` field, allowing arbitrary JavaScript execution via `dangerouslySetInnerHTML` in React. Attackers could embed the vulnerable component in a hidden iframe, triggering the exploit when a victim visited a malicious page. Once executed, the injected script sent a malicious prompt to the Claude extension, which treated it as a legitimate user command due to the trusted origin. The attack required no clicks, permissions, or visible indicators, making it nearly undetectable. Demonstrated attack scenarios included: - Theft of Google OAuth tokens (persistent access to Gmail/Drive) - Exfiltration of LLM conversation history - Silent email sending via compromised accounts Anthropic was responsibly disclosed via HackerOne on December 26, 2025, confirmed the flaw within 24 hours, and deployed a fix on January 15, 2026, replacing the wildcard allowlist with a strict `https://claude.ai` origin check. The Arkose Labs XSS was separately patched by February 19, 2026, after being reported on February 3. The incident highlights a systemic risk in AI browser agents: third-party components hosted on first-party subdomains can silently expand trust boundaries, creating exploitable attack surfaces. As AI assistants gain deeper browser access, supply chain vulnerabilities become higher-value targets for attackers.
INCIDENT DETAILS -
TYPE
Zero-Click Vulnerability, Prompt-Injection Attack
IMPACT
Data Compromised: Google OAuth tokens, Gmail/Drive access, LLM conversation history, email sending capabilitiesSystems Affected: Claude Chrome Extension, Google services (Gmail, Drive)Operational Impact: Silent hijacking of AI assistant, unauthorized data accessBrand Reputation Impact: High (silent exploitation of 3M users)Identity Theft Risk: High (Google OAuth token theft)
DATA BREACH
Authentication tokens (Google OAuth)LLM conversation historyEmail contentGoogle Drive filesSensitivity Of Data: High (PII, confidential communications, authentication tokens)Data Exfiltration: Possible (attack scenarios included exfiltration of chat histories and OAuth tokens)Text (emails, chats)Google Drive files (unspecified types)Personally Identifiable Information: Yes (email content, Google account access)
NOVEMBER 2025
752Before Incident
OCTOBER 2025
752Before Incident
SEPTEMBER 2025
752Before Incident
AUGUST 2025
752Before Incident
JULY 2025
752Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Arkose Labs ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Arkose Labs's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Arkose Labs's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Arkose Labs ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Arkose Labs's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?