On 26 August 2026 Anthropic shipped two browser products on the same day. Claude in Chrome is generally available on every paid Claude plan, and it can now take some actions without asking you each time. The same day, Cowork got a built-in browser that runs inside the desktop app and does not install an extension.
Treat them as two surfaces, not one “Claude can use the web” checkbox. Claude in Chrome acts in the browser you already signed into. The Cowork browser is Claude’s own window. Anthropic says it never sees your tabs, bookmarks, or passwords unless you copy a login over.
Which browser, and who is already signed in
- Claude in Chrome: an extension on Google Chrome. Anthropic says it can view the current page, click, type, fill forms, and move between tabs using your existing logins. It does not run on other Chromium browsers or on mobile yet.
- Cowork built-in browser: a side-panel browser in the Claude desktop app. Anthropic says it is for tasks that need a browser, not your browser: research, invoices, vendor portals with no connector.
- Login import: you can bring site logins from Chrome, Edge, or Firefox on macOS, and from Firefox on Windows and Linux. Anthropic says banking, email, and single sign-on stay out unless you include them.
- Default: if you already use Claude in Chrome, it stays the default. Otherwise Cowork uses the built-in browser. Switch under Settings, Cowork, Preferred browser.
Cowork’s browser is rolling out to Pro, Max, and Team plans in the desktop app on macOS, Windows, and Linux (Linux is in beta). Anthropic says Enterprise admins could turn it on from 26 August 2026 under Organization settings, Cowork, Built-in browser. From the web or a phone, Claude can still drive that desktop browser only while the desktop app is open and online.
Autonomy is on. The attack numbers are Anthropic’s
Claude in Chrome now auto-approves actions it judges safe, using the same idea as auto mode in Claude Code. You can turn that off and keep manual approval. A classifier, Anthropic says, checks the next action against the original request and blocks a mismatch. Enterprise admins can limit the extension to approved domains.
Anthropic published company-reported prompt-injection numbers on the Chrome post and said the Cowork browser uses the same safeguards. On an older Cowork harness, it reported no successful attacks against Fable 5, Opus 5, or Sonnet 5 even without the newer probes. It then retired that eval because it had saturated.
- On a harder red-team set, Anthropic reported that attacks which reached the model succeeded 17.6% of the time against Opus 4.5 and 3.8% against Opus 5, before extra safeguards.
- With probes plus the safety classifier, it reported no successful attacks against Sonnet 5, Opus 5, or Mythos 5, and a 0.3% success rate against Fable 5.
- It said it manually checked the remaining Fable 5 breaks, called them low-severity, and is working to mitigate them.
- The same post is explicit that prompt injection remains a moving target. The Cowork post says the safeguards reduce risk and do not eliminate it, and it tells users to start on sites they trust.
Put those percentages next to the agentic-browser same-origin write-up, not next to a marketing row. A vendor eval that reports zero on one harness and 0.3% on another is still a vendor eval. If the fleet also runs Chrome, the 3 September V8 patch is a separate clock.
What to ask before you allow either surface
- Which jobs need the user’s already-open tab, and which jobs only need an isolated browser?
- Who may turn on auto-approval, and is it off for finance, identity, and production admin consoles?
- For Enterprise, which domains are allowed in Claude in Chrome, and is the Cowork browser on or off?
- If people work from the web or a phone, is the desktop app required to be running, and who owns that dependency?
- Compare the same task on Claude, ChatGPT, and Gemini before you treat “browser use” as a single feature.
