Turning Cluely into Malware (www.hacktron.ai)

🤖 AI Summary
Security researchers have revealed a significant vulnerability in Cluely, an AI-powered Electron-based assistant, which could turn the application into a surveillance tool. Discovered in July 2025, the flaw stems from a missing navigation guard that allows the app to navigate to malicious URLs when users click on links rendered in AI-generated markdown responses. Coupled with an overly permissive IPC bridge and the lack of a Chromium sandbox, attackers can exploit this vulnerability to execute remote code, capture screenshots, and record audio without user consent. This discovery underscores the critical need for robust security measures in AI applications that have deep access to user systems. As AI agents increasingly integrate into daily workflows, the potential for exploitation grows, making it vital for developers to establish stringent vulnerability disclosure programs and implement security best practices. By highlighting these vulnerabilities, the report serves as a cautionary reminder for both developers and users about the risks associated with AI agents operating on sensitive personal data.
Loading comments...
loading comments...