Newly released consultation paper suggests “targeted reforms” such as disclosure delays and restrictions on “high-risk vendors”.
Claude extension flaw enabled silent prompt injection via XSS and weak allowlist, risking data theft and impersonation until Feb 19, 2026 fix.