Skip to content
AI Primer
release

Anthropic adds an isolated browser panel to Claude Cowork

Anthropic added an isolated browser panel to Claude Cowork for navigating websites and completing forms. The rollout begins for paid desktop users, while Claude in Chrome is now generally available.

3 min read
Anthropic adds an isolated browser panel to Claude Cowork
Anthropic adds an isolated browser panel to Claude Cowork

TL;DR

  • Cowork now opens Claude’s own side-panel browser for site navigation, reading, clicking, typing, and form filling, according to the Cowork announcement.
  • The browser keeps personal tabs, bookmarks, and passwords separate, while the rollout post says logins move over only when a user chooses to migrate them.
  • Claude in Chrome is now generally available to paid subscribers, and the Chrome availability announcement says its safety classifier evaluates browser actions before they run.

Login migration is site-by-site, with banking, email, and single sign-on excluded until explicitly included in Anthropic’s rollout post. Claude can also drive that desktop browser from the web or mobile app while the desktop app remains open and online.

The built-in browser

Cowork opens the browser only when a task needs a website, then Claude can navigate pages, read them, click, type, and submit forms in the desktop app’s side panel. Anthropic describes the target workloads in its launch post as research, dashboard lookups, and portals without connectors.

The release eliminates the extension setup for those detached web tasks. Claude in Chrome remains the route for work that starts in an existing browser tab.

Built-in browser and Claude in Chrome

The two paths divide work by where the browser state already lives. The built-in browser handles work Claude can perform in its own session, while Chrome handles the tab and account session already open in front of the user, as Anthropic’s Cowork post puts it.

Existing Claude in Chrome users retain Chrome as the default. Others default to the built-in browser, and the preference is switchable in Settings → Cowork → Preferred browser. The Chrome GA announcement says the extension can work across tabs and continue a conversation in Claude’s desktop, web, and mobile apps.

Session boundaries and availability

On macOS, logins can be migrated one site at a time from Chrome, Edge, or Firefox. Windows and Linux support migration from Firefox; Linux availability is labeled beta in the rollout details.

Pro, Max, and Team users receive the desktop rollout over the coming week on macOS, Windows, and Linux. Enterprise administrators can enable and manage the browser immediately at Organization settings → Cowork → Built-in browser, while Anthropic’s Cowork support guide documents the feature’s cross-surface availability.

Prompt injection and action checks

A browser controlled by an agent can encounter hidden instructions in pages, documents, or emails that attempt to redirect its behavior. Anthropic says Cowork’s built-in browser uses the same safeguards as Chrome, including checks that compare an action with the task the user gave it, but says those defenses cannot eliminate prompt-injection risk.

Claude in Chrome can work autonomously when its safety classifier approves an action, per the Chrome availability announcement. Its permissions guide also describes a manual mode that pauses for every action, and an automatic mode that blocks actions it judges unsafe or pauses when approval is needed. Anthropic’s safety guide calls prompt injection the biggest browser-agent risk.

Share on X