Arkose Labs A.I CyberSecurity Scoring
Arkose Labs
Company Information
Website:https://www.arkoselabs.com/?utm_source=linkedin&utm_medium=social
Employees number:250
Number of followers:16,424
NAICS:541514
Industry Type:Computer and Network Security
Homepage:arkoselabs.com
Arkose Labs Risk Score (AI oriented)
Between 750 and 799
Arkose LabsComputer and Network Security
Updated:
27/03/2026
27/03/2026
752/1000
Fair
Baa
Arkose Labs Global Score (TPRM)
xxxx
Arkose LabsComputer and Network Security
Score locked

Arkose LabsFair
Current Score
752Baa (FAIR)
01000
1 incidents
-1 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
752
MAY 2026
752
APRIL 2026
752
MARCH 2026
752
FEBRUARY 2026
751
JANUARY 2026
751
DECEMBER 2025
752
Vulnerability
26 Dec 2025 • Arkose Labs
Anthropic and Arkose Labs: Claude Chrome Extension 0-Click Vulnerability Enables Silent Prompt Injection Attacks
Critical Zero-Click Vulnerability in Claude Chrome Extension Exposed 3M Users to Silent Hijacking
751
CRITICAL-1
ANTARK1774585435
Critical Zero-Click Vulnerability in Claude Chrome Extension Exposed 3M Users to Silent Hijacking
A now-patched zero-click vulnerability in Anthropic’s Claude Chrome Extension left over 3 million users vulnerable to silent prompt-injection attacks, enabling malicious actors to hijack the AI assistant without any user interaction. The exploit, discovered by KOI Security, could have allowed attackers to steal Gmail access tokens, read Google Drive files, export chat histories, and send emails all invisibly.
The attack chain leveraged two critical flaws:
1. Overly Permissive Origin Allowlist – The extension’s messaging API accepted prompts from any `.claude.ai` subdomain, including third-party components like Arkose Labs’ CAPTCHA verification*, which was hosted on `a-cdn.claude.ai`.
2. DOM-Based XSS in Arkose CDN – An older, predictable version of the CAPTCHA component contained an unsanitized `stringTable` field, allowing arbitrary JavaScript execution via `dangerouslySetInnerHTML` in React. Attackers could embed the vulnerable component in a hidden iframe, triggering the exploit when a victim visited a malicious page.
Once executed, the injected script sent a malicious prompt to the Claude extension, which treated it as a legitimate user command due to the trusted origin. The attack required no clicks, permissions, or visible indicators, making it nearly undetectable.
Demonstrated attack scenarios included:
- Theft of Google OAuth tokens (persistent access to Gmail/Drive)
- Exfiltration of LLM conversation history
- Silent email sending via compromised accounts
Anthropic was responsibly disclosed via HackerOne on December 26, 2025, confirmed the flaw within 24 hours, and deployed a fix on January 15, 2026, replacing the wildcard allowlist with a strict `https://claude.ai` origin check. The Arkose Labs XSS was separately patched by February 19, 2026, after being reported on February 3.
The incident highlights a systemic risk in AI browser agents: third-party components hosted on first-party subdomains can silently expand trust boundaries, creating exploitable attack surfaces. As AI assistants gain deeper browser access, supply chain vulnerabilities become higher-value targets for attackers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
NOVEMBER 2025
752
OCTOBER 2025
752
SEPTEMBER 2025
752
AUGUST 2025
752
JULY 2025
752
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Arkose Labs ??
What was Arkose Labs's A.I Rankiteo Cyber Score in May 2026 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in April 2026 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in March 2026 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in February 2026 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in January 2026 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in December 2025 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in November 2025 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in October 2025 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in September 2025 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in August 2025 ??
What was Arkose Labs's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Arkose Labs's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Arkose Labs ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Arkose Labs's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?