0-Click RCE in Claude Desktop Extensions: What to Do
A 0-click RCE in Claude Desktop Extensions runs system commands with no user interaction. Learn the risk and the immediate steps to protect endpoints.
Yossi Pinhasov
YouCC Technologies
0-Click RCE in Claude Desktop Extensions
A zero-click remote code execution (RCE) vulnerability has been disclosed in Claude Desktop Extensions. The attack requires no user interaction: a malicious calendar event is read by Claude, which then executes system commands with the user's own permissions. Because no click or approval is needed, this is a high-severity issue for any endpoint running the affected extensions.
What happened
The exploit chain starts with attacker-controlled content reaching the AI assistant. A crafted calendar event is ingested by Claude, and the embedded instructions trigger execution of system commands on the host. The action runs with the privileges of the logged-in user, so there is no privilege barrier between the malicious input and the operating system.
Why it matters
The impact is the full range of endpoint compromise:
- Local code execution on the user's machine
- Data theft from the device and connected accounts
- Lateral movement across the network
- Privilege abuse on endpoints
The zero-click nature is what makes it dangerous. There is no suspicious prompt to dismiss and no obvious user mistake to blame — the assistant processes hostile content automatically. This is a clear example of why AI tools with broad access to local data must be treated as part of the attack surface.
What to do
Take these immediate steps:
- Update Claude and all extensions to the latest patched versions.
- Disable automatic AI access to calendars, email, and external sources, granting it deliberately rather than by default.
Review the full technical write-up at Cyber Security News.
Shared from the CSC - Cloud Security Community community, by Yossi Pinhasov.
Want more like this? Join the CSC - Cloud Security Community → https://youcc.co.il/community