China Warns Users of ‘Security Backdoor Vulnerabilities’ in Anthropic’s Claude Code

China’s National Vulnerability Database has issued a warning about Anthropic’s Claude Code, citing potential spyware features. The database highlighted concerns over user information being transmitted to Anthropic servers without explicit consent, including sensitive data like user identity and geographic location. Alibaba recently took action by banning the internal use of Claude Code due to fears of data leakage and IP exposure.

Anthropic has been accused of collecting user data without authorization, leading to concerns about privacy and enterprise security risks. While the company denies the presence of malicious spyware, it has acknowledged certain functionalities that could be perceived as a security risk. Alibaba engineers conducted a detailed analysis of Claude Code, uncovering specific checks related to Chinese system time zones and network characteristics.

In response to the security concerns raised by Chinese authorities, users are being advised to uninstall vulnerable versions of Claude Code and switch to updated releases that address these issues. The National Vulnerability Database identified affected versions ranging from 2.1.91 to 2.1.196, prompting the need for immediate action to mitigate potential risks.


Comments

Leave a Reply

Your email address will not be published. Required fields are marked *