In a significant development, China issued a warning on Wednesday regarding the potential security vulnerabilities associated with Anthropic's Claude Code artificial intelligence tool, which is developed by the U.S.-based firm. This warning surfaces amidst escalating tensions in the tech domain between the U.S. and China. Last month, Anthropic accused the Chinese giant Alibaba of attempting to acquire its AI capabilities, which are not legally accessible in China; Alibaba has yet to respond to these allegations.
Despite the restrictions, numerous individuals and organizations in China have circumvented barriers to utilize U.S. AI technologies. In a state-organized conference in March, a developer from Xiaomi revealed that many users had adopted Claude Code. Moreover, CNBC confirmed that Alibaba has directed its staff to cease using Anthropic's tools for work purposes as of July 10.
The Chinese Ministry of Industry and Information Technology announced on Wednesday that its cybersecurity monitoring platform identified a “back-door” vulnerability in the Claude Code AI tool, raising significant concerns regarding data security. This flaw reportedly allows the automatic coding tool to transmit sensitive user information—such as location and personal identity—to a remote server without obtaining explicit user consent.
In light of these findings, the cybersecurity platform recommended that users uninstall or update any affected versions of Claude Code, specifically those ranging from 2.1.91 to 2.1.196, which were released between April 2 and June 29. The latest version, 2.1.204, is currently available, as noted on Anthropic's website. Anthropic has yet to respond to requests from CNBC for further comments on this issue.



