Claude Desktop privacy concerns have emerged after Anthropic’s Claude Desktop for macOS installs files that modify other vendors’ applications without disclosure or user permission, according to privacy consultant Alexander Hanff. The artificial intelligence application pre-authorizes browser extensions and creates integration files for browsers not yet installed on users’ devices, raising significant concerns about consent and regulatory compliance.
Hanff discovered the undisclosed file installation while debugging another application that used Native Messaging, an API for communicating between Chrome and other applications. Claude Desktop installed a Native Messaging manifest file named com.anthropic.claude_browser_extension.json that pre-authorizes three different Chrome extension identifiers, including Claude in Chrome extension. This file enables browsers to run a local executable without explicit user consent, allowing Claude to access various browsers for automated operation.
Claude Desktop privacy violations explained
Hanff contends that Claude Desktop’s installation process violates Article 5(3) of the ePrivacy Directive, which requires service providers to obtain explicit consent before accessing a person’s data. The manifest file sets up automated access to browsers the user has not actively chosen to integrate with Claude Desktop. This happens invisibly by default, with no opt-in mechanism and difficult removal options.
The Claude in Chrome extension carries broad permissions, including authenticated session access, the ability to read web pages, fill out forms, and capture the screen. More concerning, the binary bridge application runs outside the browser’s sandbox at user privilege level without surfacing any permission prompts. Hanff notes that Anthropic’s own safety data indicates Claude for Chrome has a 23.6 percent success rate for prompt injection attacks without mitigations, and 11.2 percent with current mitigations, creating a potential security pathway from the extension through the bridge to the helper binary.
Expert analysis on security and legal implications
Noah M. Kenney, founder of advisory firm Digital 520, confirms that Hanff’s technical findings appear reproducible and verifiable. Independent reviewers can confirm that identical Native Messaging manifests are written across multiple Chromium-based browser paths and that installation events are recorded in the application’s logs. Kenney notes the cybersecurity risk is substantial, as this creates a persistent pre-authorized bridge from browser extensions into a local executable running outside the browser sandbox.
“Users do not expect a desktop application to silently modify other applications, especially across vendors. European regulators, in particular, expect explicit opt-in, installation scoped only to user-selected integrations, and clear persistent controls with real revocation.”
Noah M. Kenney, Digital 520
Regarding the legal implications, Kenney explains that Article 5(3) of the ePrivacy Directive clearly applies to storing information on a user’s device. However, the key question is whether silently installing cross-application integrations is strictly necessary for a service the user requested. European regulators tend to interpret “strictly necessary” narrowly, meaning this implementation likely falls outside regulatory exemptions and carries credible enforcement risk.
Industry trust and regulatory scrutiny
Kenney distinguishes between Hanff’s use of the term “spyware” and the actual technical behavior. Traditional spyware implies active and covert data exfiltration, whereas Claude Desktop creates a dormant pre-positioned integration layer that only activates when triggered by a browser extension. Nonetheless, the attack surface expansion and trust boundary violation remain significant concerns from a security perspective.
European enforcement is increasingly focused on demonstrable, user-visible control rather than implied or deferred consent. Silent system modification across application boundaries represents precisely the pattern regulators are targeting. Kenney warns that beyond legal ramifications, Anthropic faces substantial reputational damage and loss of user trust, particularly given the company’s public positioning around safety and privacy. Hanff stated he has not filed a formal complaint but intends to do so if Anthropic fails to address the Claude Desktop installation process. Anthropic did not respond to requests for comment.
Outlook
The Claude Desktop controversy highlights growing tensions between software integration practices and evolving privacy regulations. As European regulators intensify scrutiny of cross-application modifications and implicit consent mechanisms, technology companies face pressure to redesign their installation and authorization workflows. Anthropic’s handling of this issue will likely influence how other software applications approach browser integrations and system-level modifications going forward.
Source: theregister.com





