LayerX researchers found a zero-click vulnerability in Claude Desktop Extensions (CVSS 10.0) that could execute code via a malicious Google Calendar event. The flaw stems from tool chaining with full system privileges and no sandboxing. Anthropic declined to fix it.