According to a report by ithome.com.tw citing security firm Malwarebytes, Anthropic's Claude chatbot has a share-chat feature that sets conversations to 'Public' status, which can then be indexed by Google Search — a flaw Malwarebytes says also previously affected Grok and Meta AI. The report notes the issue was first surfaced by Reddit users searching Google, and Malwarebytes recommends users avoid sharing chats or personal data with AI tools altogether.
How does Claude's share-chat feature lead to Google indexing of sensitive conversations?
According to a report by ithome.com.tw dated August 7, 2026, security firm Malwarebytes said Anthropic's AI chatbot Claude has a share-chat feature that can result in conversations being found through Google Search, exposing sensitive information contained in those chats (E1). The report traces the root cause to Claude's Share Chats function: citing Anthropic's own documentation, the feature generates a shareable link for a conversation and simultaneously changes that conversation's status to "Public" (E3). Once a chat is set to Public via a share link, it becomes accessible to anyone who has the link — and, as the report describes, also becomes reachable by search engine crawlers.
How was the problem discovered, and how are leaked conversations being found on Google?
The ithome.com.tw report states that the issue was first identified by Reddit users, who found that using specific search techniques on Google turned up numerous Claude conversation logs in search results (E2). This user-driven discovery — rather than a formal security audit — was how the exposure came to public attention, according to the report.
Is this problem unique to Claude, or have other AI services had similar issues?
Malwarebytes told ithome.com.tw that this is not a Claude-only problem. The firm said it had previously found conversation logs from xAI's Grok appearing in Google search results, and that Meta AI had exhibited a similar issue in the past (E4). This places the Claude share-link exposure within a pattern the security firm says it has observed across more than one AI chat product, based on its own prior findings.
What should users do to prevent sensitive information from leaking through AI chat-sharing features?
Per the same report, Malwarebytes' recommendation is direct: the simplest way to avoid sensitive data leaking through this kind of shared-conversation exposure is to not share AI conversations with anyone at all, or to avoid entering personally identifiable information into an AI chat in the first place (E5). The firm frames this as a user-behavior mitigation rather than something that depends on a platform fix.
How does the "zero training" setting affect the risk of information exposure across AI platforms?
A separate report on futurecity.cw.com.tw, dated May 21, 2026, describes how default "zero training" configurations vary by platform. It notes that ChatGPT's default setting has training turned on, requiring users to manually switch it off; Claude similarly requires users to confirm and adjust the setting; and for Gemini, the personal version offers no way to adjust this setting at all, while the enterprise version defaults to it being off (E9). This means the baseline risk of a user's input being retained or used for training differs depending on which product and which tier (personal vs. enterprise) a user is on, according to the report.
How does user misunderstanding about where AI computation happens lead to accidental exposure of sensitive information?
The same futurecity.cw.com.tw report cites the example of OpenClaw, where it says many users mistakenly believe that model computation is happening locally on their Mac Mini device. In reality, according to the report, information is still sent out to an external AI model — and it notes that some users have directly entered highly sensitive personal data, including health insurance card information, into the tool under this false assumption (E10).
What this means
Taken together, the evidence points to two distinct but related exposure paths. First, Claude's share-chat design (E1, E3) turns a convenience feature — generating a link to show someone else a conversation — into a public, search-indexable page, a pattern Malwarebytes says it has also seen with Grok and Meta AI (E4), and which was first surfaced not by a formal audit but by Reddit users searching Google (E2). Malwarebytes' own recommended fix for this — simply not sharing chats or personal data (E5) — addresses the sharing-link vector specifically. Second, separate reporting on default "zero training" settings (E9) and on user misunderstanding about where computation actually occurs, as in the OpenClaw case (E10), suggests that avoiding the share button alone would not close every exposure gap: even conversations that are never shared via a link can still leave the device and reach an external model, depending on platform defaults and user assumptions about local versus remote processing.