The vulnerability was first identified by Reddit users who discovered that basic search operators, such as “site:claude.ai/share,” bypassed the intended privacy of the chat-sharing tool. While Anthropic maintains that its system does not provide sitemaps or directories to search engines, the indexed content included highly confidential data, ranging from patient names in clinical trial results to internal employee reviews and school-aged children’s contact details. Reports also surfaced of the model generating prohibited content, including erotica, within the exposed shared sessions.
Anthropic spokesperson Amie Rotherham stated that the company does not share chat directories with search engines, suggesting that links only appeared in results after being posted elsewhere by users. Google spokesperson Ned Adriance countered this, noting that search engines index pages based on site owner directives and do not control which content is made public. By Monday afternoon, the index appeared to be remediated, though the incident mirrors similar privacy lapses involving ChatGPT and previous Claude iterations. Users are advised to audit their shared link history via the Settings menu under the Privacy tab to ensure no sensitive conversations remain publicly accessible.

Comments (0)
No comments yet. Be the first!