Anthropic has turned the Claude in Chrome side panel into a full Claude Cowork session, connecting browser-based work with the company’s desktop, web and mobile apps.
The change means conversations started in Chrome are now saved to a user’s Claude history, while configured skills and connectors also work in the browser. A task started in Chrome can then be continued from another Claude app without losing its context.
The feature is now rolling out to users on Anthropic’s Max and Team plans. Pro subscribers are expected to receive access in the coming weeks. For Enterprise customers, the extension is disabled by default. Administrators can choose to enable it and restrict its use to specific domains, giving organizations more control over where the browser assistant can operate.
Claude in Chrome can see the page a user is viewing and perform actions such as clicking links, navigating between pages, entering text, and filling out forms using existing browser logins.
That gives Claude a way to work with systems that may not have direct integrations, including internal dashboards, legacy applications and vendor portals. Anthropic said the extension currently works only in Chrome. It does not run in other Chromium-based browsers or on mobile devices, limiting its availability beyond Google’s browser ecosystem.
The convenience comes with a security problem
Giving an AI agent access to websites also creates a major security challenge: prompt injection.
Malicious instructions can be hidden in web pages, emails or documents and potentially trick an agent into taking actions that the user never requested. Anthropic says Claude in Chrome now has a separate check for its own actions when automatic approval is enabled.
That check reviews consequential actions, such as submitting forms, sending messages or downloading files, against the user's original request. Claude will still ask for confirmation before certain irreversible or costly actions, including purchases and sharing personal data.
The company also acknowledged that browser-based AI agents still carry risks, saying that “while these measures meaningfully reduce the risk, they cannot eliminate it.”
What this means for users
The update pushes Claude further into the everyday browser workflows where research, purchases, forms and internal tools already live. That could make the assistant more useful, especially when no direct integration exists, but it also means users and IT teams need to treat browser access as a meaningful permission rather than a convenience toggle.
Anthropic’s added checks reduce some of the risk, but its own warning is the important takeaway: browser agents still need oversight when they can act inside authenticated sessions.
More News: Anthropic is adding watermarks to Claude-generated content in Europe as new EU AI transparency rules take effect, highlighting how regulation is beginning to shape the way AI companies label synthetic material.


