A macOS Keychain implementation weakness in Anthropic’s Claude Code CLI could allow any process running as the logged-in user including a Claude Code-spawned child process to retrieve the tool’s OAuth credential bundle silently. The issue underscores how trusted AI coding-agent ancestry can mask high-impact credential access and persistence activity on developer endpoints. However, the CLI […] The post Claude Code Child Process Can Read Its Own OAuth Token From macOS Keychain appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
First seen on gbhackers.com
Jump to article: gbhackers.com/macos-keychain-access/
![]()

