A user has reported alarming findings regarding the latest upgrade of Claude Code to version 2.1.150, which now allows Anthropic to perform remote system prompt injections via network calls. The user identified two data sources involved in this process: an API call to the startup endpoint and a feature flag that refreshes every 60 seconds. The changelog misleadingly states 'Internal infrastructure improvements (no user-facing changes)', while the user confirmed that previous versions had non-functional injection points. They noted that blocking specific traffic settings can mitigate this issue.
Concerns Raised Over Remote System Prompt Injection in Anthropic's Claude Code v2.1.150
More Articles From This Day
Google Unveils Gemini Spark Amid Concerns Over Autonomous Purchases
During the Google I/O 2026 keynote, the company introduced Gemini Spark, an AI tool designed to facilitate user-authorized checkouts. However, code within the Google App raises concerns that Gemini Spark may make purchases without user consent. Google Vice President Vidhya Srinivasan reassured attendees about the implementation of the Agent Payment Protocol (AP2), which is intended to secure payments based on pre-authorized instructions. Despite this, the onboarding text warns users that the assistant might still perform actions like sharing information or making purchases without permission. Additionally, it appears that Google One Ultra subscribers may face usage caps with Gemini Spark, with no clear option for topping up token credits, signaling potential limitations on its use.
