Threat · curated 7 Jul 2026

Red teamers turned Claude Desktop into a double agent to do their evil bidding

Coverage timeline

1 Jul 2026theregister.com 15 Jul 2026darkreading.com 16 Jul 2026oasis.security

Why it matters

PromptFiction shows how a custom URL scheme plus MCP tool access can turn an AI desktop assistant into an automated attack channel reaching local files and code execution, a class of agentic risk defenders must account for.

Oasis Security disclosed "PromptFiction," a vulnerability in Anthropic's Claude Desktop where a single click on a trusted-looking claude:// URL silently submitted attacker-controlled prompts to the assistant with no user confirmation. Chained with the earlier "Claudy Day" trio of flaws, it could enable silent exfiltration of prior conversations and — when Anthropic's official Filesystem MCP server is installed — file read/write, persistence, and remote code execution. Anthropic has fixed the flaw.