Anthropic旗下AI助手Claude的共享聊天功能存在安全漏洞,导致大量用户对话被谷歌搜索引擎公开索引[1]。使用搜索操作符"site:claude.ai/share"可以在Google上发现这些共享对话[1]。泄露内容涉及多种敏感信息,包括详细医疗报告、临床试验结果、包含儿童姓名和电话号码的文件、公司内部文件和员工评论[1]。
Anthropic发言人Amie Rotherham表示,公司"向用户提供了控制权来公开分享其Claude对话,遵循我们的隐私原则,我们不与谷歌等搜索引擎共享聊天目录或网站地图"[1]。去年Forbes曾报道谷歌索引了接近600份Claude对话[1]。周一下午的测试表明该问题已得到修复,搜索不再返回相关结果[1]。
Anthropic's Claude AI assistant experienced a significant privacy vulnerability in which thousands of user-shared conversations and Artifacts were being publicly indexed by Google Search.[1] The leaked content included sensitive information such as detailed medical reports, clinical trial results, files containing children's names and phone numbers, internal company documents, and employee reviews.[1]
The issue came to light when researchers discovered that using the search operator "site:claude.ai/share" on Google returned numerous shared conversations.[1] According to Anthropic spokesperson Amie Rotherham, the company stated: "We give people control over sharing their Claude conversations publicly, and in keeping with our privacy principles, we do not share chat directories or sitemaps with search engines like Google."[1] Despite this assertion, Google's position was that the company does not control the public status of web pages.[1]
By Monday afternoon, Anthropic had resolved the issue, with testing confirming that the search operator no longer returned results.[1] The incident echoed previous security concerns, as Forbes had reported that Google had indexed approximately 600 Claude conversations, while 404 Media documented that researchers were able to scrape roughly 100,000 publicly shared ChatGPT conversations.[1]